• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Pretend Financial institution of America Phishing Emails Discovered Delivering Disguised ScreenConnect RAT by way of UAC Bypass

Admin by Admin
August 5, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Researchers at Huntress have recognized an energetic phishing marketing campaign impersonating Financial institution of America that culminates within the covert set up of a distant monitoring and administration (RMM) instrument, giving attackers persistent, hard-to-detect entry to victims’ Home windows machines.



The marketing campaign was flagged after a message landed in considered one of Huntress’s spamtrap accounts on 28 July, despatched from a spoofed deal with designed to resemble a reputable Financial institution of America area. The e-mail makes use of a well-recognized social-engineering hook: a time-limited warning urging the recipient to “affirm” their account particulars or danger restrictions being positioned on it.

Gadget-dependent payloads

In keeping with Huntress’s evaluation, the phishing infrastructure fingerprints the visiting system and serves totally different content material accordingly. Mac customers, or anybody with a non-Home windows person agent, are proven a traditional credential-harvesting web page that additionally solicits full mailing addresses, authorities ID numbers, Social Safety numbers, and card cost particulars. Home windows customers are as an alternative prompted to obtain and run “Account Guard,” described on the faux web page as safety software program, however which is actually a Trojanised installer for ScreenConnect, a reputable RMM instrument continuously abused by risk actors.

Layered obfuscation and a UAC bypass

The downloaded archive incorporates a Visible Fundamental Script that kicks off a prolonged decoding chain, with base64-encoded payloads nested inside each other throughout a number of levels earlier than a ultimate PowerShell script is executed. That script retrieves a 17MB ScreenConnect installer from a public file-sharing website and decrypts two AES-128-CBC-protected information blobs bundled inside it.

One blob decodes to C# supply that Huntress says seems to have been lifted straight from a public GitHub proof-of-concept. It exploits the ICMLuaUtil Elevated COM interface, a identified Consumer Account Management (UAC) bypass approach mapped to MITRE ATT&CK T1548.002, permitting the ScreenConnect installer to run with Administrator privileges with out ever triggering the UAC immediate customers are educated to note.

The second blob decodes to a VBScript that deletes the registry key pointing to the installer and applies Safety Descriptor Definition Language (SDDL) strings and entry management lists that stop the service, put in beneath the disguised title “Home windows Safety”, from being seen, disabled, or eliminated, even by directors. The compromised host then reaches out to a command-and-control deal with within the United Arab Emirates over port 8041/tcp.

Detection and mitigation

Huntress notes that the marketing campaign is detectable at its earliest stage: neither the sending area nor the embedded redirect hyperlink factors to Financial institution of America’s real infrastructure, a discrepancy seen within the browser deal with bar earlier than any file is downloaded. The agency has revealed full indicators of compromise, together with the malicious domains, the C2 IP deal with, and file hashes, to its GitHub repository, and recommends organisations monitor for unauthorised ScreenConnect installations and strange SDDL/ACL modifications on endpoint providers.

The findings add to a rising physique of proof that RMM abuse stays a most well-liked approach for risk actors searching for persistent entry whereas evading conventional malware detection, notably when paired with brand-impersonation phishing that mimics a goal firm’s visible identification carefully sufficient to go informal inspection.

Tags: AmericaBankBypassDeliveringDisguisedemailsFakePhishingRATScreenConnectUAC
Admin

Admin

Next Post
These Lord of the Rings 3D Maps Are an Unimaginable Present Concept for Tolkien Followers

These Lord of the Rings 3D Maps Are an Unimaginable Present Concept for Tolkien Followers

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

The right way to use Netdiscover to map and troubleshoot networks

The right way to use Netdiscover to map and troubleshoot networks

August 26, 2025
Learn how to Develop an App Like Uber in 2026

Learn how to Develop an App Like Uber in 2026

May 8, 2026
Prime AI Legacy System Modernization Firms in 2026

Prime AI Legacy System Modernization Firms in 2026

July 10, 2026
Why Your Web site is Failing to Convert—and How a Net App Can Save the Day

Why Your Web site is Failing to Convert—and How a Net App Can Save the Day

April 2, 2025
The Visible Haystacks Benchmark! – The Berkeley Synthetic Intelligence Analysis Weblog

The Visible Haystacks Benchmark! – The Berkeley Synthetic Intelligence Analysis Weblog

May 2, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

These Lord of the Rings 3D Maps Are an Unimaginable Present Concept for Tolkien Followers

These Lord of the Rings 3D Maps Are an Unimaginable Present Concept for Tolkien Followers

August 5, 2026
Pretend Financial institution of America Phishing Emails Discovered Delivering Disguised ScreenConnect RAT by way of UAC Bypass

Pretend Financial institution of America Phishing Emails Discovered Delivering Disguised ScreenConnect RAT by way of UAC Bypass

August 5, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved