Researchers at Huntress have recognized an energetic phishing marketing campaign impersonating Financial institution of America that culminates within the covert set up of a distant monitoring and administration (RMM) instrument, giving attackers persistent, hard-to-detect entry to victims’ Home windows machines.
The marketing campaign was flagged after a message landed in considered one of Huntress’s spamtrap accounts on 28 July, despatched from a spoofed deal with designed to resemble a reputable Financial institution of America area. The e-mail makes use of a well-recognized social-engineering hook: a time-limited warning urging the recipient to “affirm” their account particulars or danger restrictions being positioned on it.
Gadget-dependent payloads
In keeping with Huntress’s evaluation, the phishing infrastructure fingerprints the visiting system and serves totally different content material accordingly. Mac customers, or anybody with a non-Home windows person agent, are proven a traditional credential-harvesting web page that additionally solicits full mailing addresses, authorities ID numbers, Social Safety numbers, and card cost particulars. Home windows customers are as an alternative prompted to obtain and run “Account Guard,” described on the faux web page as safety software program, however which is actually a Trojanised installer for ScreenConnect, a reputable RMM instrument continuously abused by risk actors.
Layered obfuscation and a UAC bypass
The downloaded archive incorporates a Visible Fundamental Script that kicks off a prolonged decoding chain, with base64-encoded payloads nested inside each other throughout a number of levels earlier than a ultimate PowerShell script is executed. That script retrieves a 17MB ScreenConnect installer from a public file-sharing website and decrypts two AES-128-CBC-protected information blobs bundled inside it.
One blob decodes to C# supply that Huntress says seems to have been lifted straight from a public GitHub proof-of-concept. It exploits the ICMLuaUtil Elevated COM interface, a identified Consumer Account Management (UAC) bypass approach mapped to MITRE ATT&CK T1548.002, permitting the ScreenConnect installer to run with Administrator privileges with out ever triggering the UAC immediate customers are educated to note.
The second blob decodes to a VBScript that deletes the registry key pointing to the installer and applies Safety Descriptor Definition Language (SDDL) strings and entry management lists that stop the service, put in beneath the disguised title “Home windows Safety”, from being seen, disabled, or eliminated, even by directors. The compromised host then reaches out to a command-and-control deal with within the United Arab Emirates over port 8041/tcp.
Detection and mitigation
Huntress notes that the marketing campaign is detectable at its earliest stage: neither the sending area nor the embedded redirect hyperlink factors to Financial institution of America’s real infrastructure, a discrepancy seen within the browser deal with bar earlier than any file is downloaded. The agency has revealed full indicators of compromise, together with the malicious domains, the C2 IP deal with, and file hashes, to its GitHub repository, and recommends organisations monitor for unauthorised ScreenConnect installations and strange SDDL/ACL modifications on endpoint providers.
The findings add to a rising physique of proof that RMM abuse stays a most well-liked approach for risk actors searching for persistent entry whereas evading conventional malware detection, notably when paired with brand-impersonation phishing that mimics a goal firm’s visible identification carefully sufficient to go informal inspection.







