Bank of America Phishing Email Delivers ScreenConnect Malware
ID: 3a287040-d777-5231-aa00-f0d5c03ee425
STIX ID: report--3a287040-d777-5231-aa00-f0d5c03ee425
Feed Name: Huntress Blog
Huntress observed a phishing campaign impersonating Bank of America that delivers an AccountGuardSetup.vbs file; the VBScript decodes nested base64/PowerShell stages, downloads a base64-encoded ScreenConnect .msi, decrypts and compiles C# code to perform an ICMLuaUtil UAC bypass, and applies SDDL/ACL changes to hide and lock the installed RMM, connecting to a C2 at 217.60.195.167. IOCs (file hashes, domains, URLs, drop path, and C2 IP) are provided for detection and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
