International Cyber Expo International Cyber Expo
  • About Us
Friday, 18 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass

by Guru Writer
August 4, 2026
in News
Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
Share on FacebookShare on Twitter

Researchers at Huntress have identified an active phishing campaign impersonating Bank of America that culminates in the covert installation of a remote monitoring and management (RMM) tool, giving attackers persistent, hard-to-detect access to victims’ Windows machines.

The campaign was flagged after a message landed in one of Huntress’s spamtrap accounts on 28 July, sent from a spoofed address designed to resemble a legitimate Bank of America domain. The email uses a familiar social-engineering hook: a time-limited warning urging the recipient to “confirm” their account details or risk restrictions being placed on it.

Device-dependent payloads

According to Huntress’s analysis, the phishing infrastructure fingerprints the visiting device and serves different content accordingly. Mac users, or anyone with a non-Windows user agent, are shown a conventional credential-harvesting page that also solicits full mailing addresses, government ID numbers, Social Security numbers, and card payment details. Windows users are instead prompted to download and run “Account Guard,” described on the fake page as protection software, but which is in fact a Trojanised installer for ScreenConnect, a legitimate RMM tool frequently abused by threat actors.

Layered obfuscation and a UAC bypass

The downloaded archive contains a Visual Basic Script that kicks off a lengthy decoding chain, with base64-encoded payloads nested inside one another across several stages before a final PowerShell script is executed. That script retrieves a 17MB ScreenConnect installer from a public file-sharing site and decrypts two AES-128-CBC-protected data blobs bundled within it.

One blob decodes to C# source that Huntress says appears to have been lifted directly from a public GitHub proof-of-concept. It exploits the ICMLuaUtil Elevated COM interface, a known User Account Control (UAC) bypass technique mapped to MITRE ATT&CK T1548.002, allowing the ScreenConnect installer to run with Administrator privileges without ever triggering the UAC prompt users are trained to notice.

The second blob decodes to a VBScript that deletes the registry key pointing to the installer and applies Security Descriptor Definition Language (SDDL) strings and access control lists that prevent the service, installed under the disguised name “Windows Security”, from being viewed, disabled, or removed, even by administrators. The compromised host then reaches out to a command-and-control address in the United Arab Emirates over port 8041/tcp.

Detection and mitigation

Huntress notes that the campaign is detectable at its earliest stage: neither the sending domain nor the embedded redirect link points to Bank of America’s genuine infrastructure, a discrepancy visible in the browser address bar before any file is downloaded. The firm has published full indicators of compromise, including the malicious domains, the C2 IP address, and file hashes, to its GitHub repository, and recommends organisations monitor for unauthorised ScreenConnect installations and unusual SDDL/ACL modifications on endpoint services.

The findings add to a growing body of evidence that RMM abuse remains a preferred technique for threat actors seeking persistent access while evading traditional malware detection, particularly when paired with brand-impersonation phishing that mimics a target company’s visual identity closely enough to pass casual inspection.

ShareTweet
Previous Post

When AI Agents Meet Real Infrastructure: Hype, Human Error or a Genuine New Threat?

Next Post

Identity Verification Is Becoming The Real Signature

Recent News

Filigran Backs Security Serious Unsung Heroes Awards as New Sponsor

Filigran Backs Security Serious Unsung Heroes Awards as New Sponsor

September 18, 2026
Four AI Agent Security Risks Organisations Can’t Afford to Ignore

Four AI Agent Security Risks Organisations Can’t Afford to Ignore

September 18, 2026
New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence

New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence

September 17, 2026
When Everyday Habits Become an Invisible Security Risk

When Everyday Habits Become an Invisible Security Risk

September 17, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol