logo

Bank of America Phishing Email Delivers ScreenConnect Malware

ID: 3a287040-d777-5231-aa00-f0d5c03ee425

STIX ID: report--3a287040-d777-5231-aa00-f0d5c03ee425

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2026-08-04

Date Updated: 2026-08-19

...
...

Huntress observed a phishing campaign impersonating Bank of America that delivers an AccountGuardSetup.vbs file; the VBScript decodes nested base64/PowerShell stages, downloads a base64-encoded ScreenConnect .msi, decrypts and compiles C# code to perform an ICMLuaUtil UAC bypass, and applies SDDL/ACL changes to hide and lock the installed RMM, connecting to a C2 at 217.60.195.167. IOCs (file hashes, domains, URLs, drop path, and C2 IP) are provided for detection and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.