{"id":17429,"date":"2026-08-05T08:11:02","date_gmt":"2026-08-05T08:11:02","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17429"},"modified":"2026-08-05T08:11:02","modified_gmt":"2026-08-05T08:11:02","slug":"pretend-financial-institution-of-america-phishing-emails-discovered-delivering-disguised-screenconnect-rat-by-way-of-uac-bypass","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17429","title":{"rendered":"Pretend Financial institution of America Phishing Emails Discovered Delivering Disguised ScreenConnect RAT by way of UAC Bypass"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Researchers at <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.huntress.com\/\">Huntress<\/a> have recognized an energetic phishing marketing campaign impersonating Financial institution of America that culminates within the covert set up of a distant monitoring and administration (RMM) instrument, giving attackers persistent, hard-to-detect entry to victims\u2019 Home windows machines.<\/p>\n<div class=\"jeg_ad jeg_ad_article jnews_content_inline_ads  \">\n<div class=\"ads-wrapper align-right \"><a rel=\"nofollow\" target=\"_blank\" href=\"http:\/\/bit.ly\/jnewsio\" aria-label=\"Visit advertisement link\" target=\"_blank\" rel=\"nofollow noopener\" class=\"adlink ads_image align-right\"><br \/>\n                                    <img decoding=\"async\" class=\"lazyload\" src=\"https:\/\/itsecguru.dessol.com\/wp-content\/uploads\/2018\/08\/ad_300x250.jpg\" alt=\"\" data-pin-no-hover=\"true\"\/><br \/>\n                                <\/a><\/div>\n<\/div>\n<p>The marketing campaign was flagged after a message landed in considered one of Huntress\u2019s spamtrap accounts on 28 July, despatched from a spoofed deal with designed to resemble a reputable Financial institution of America area. The e-mail makes use of a well-recognized social-engineering hook: a time-limited warning urging the recipient to \u201caffirm\u201d their account particulars or danger restrictions being positioned on it.<\/p>\n<h4><strong>Gadget-dependent payloads<\/strong><\/h4>\n<p>In keeping with Huntress\u2019s evaluation, the phishing infrastructure fingerprints the visiting system and serves totally different content material accordingly. Mac customers, or anybody with a non-Home windows person agent, are proven a traditional credential-harvesting web page that additionally solicits full mailing addresses, authorities ID numbers, Social Safety numbers, and card cost particulars. Home windows customers are as an alternative prompted to obtain and run \u201cAccount Guard,\u201d described on the faux web page as safety software program, however which is actually a Trojanised installer for ScreenConnect, a reputable RMM instrument continuously abused by risk actors.<\/p>\n<h4><strong>Layered obfuscation and a UAC bypass<\/strong><\/h4>\n<p>The downloaded archive incorporates a Visible Fundamental Script that kicks off a prolonged decoding chain, with base64-encoded payloads nested inside each other throughout a number of levels earlier than a ultimate PowerShell script is executed. That script retrieves a 17MB ScreenConnect installer from a public file-sharing website and decrypts two AES-128-CBC-protected information blobs bundled inside it.<\/p>\n<p>One blob decodes to C# supply that Huntress says seems to have been lifted straight from a public GitHub proof-of-concept. It exploits the ICMLuaUtil Elevated COM interface, a identified Consumer Account Management (UAC) bypass approach mapped to MITRE ATT&amp;CK T1548.002, permitting the ScreenConnect installer to run with Administrator privileges with out ever triggering the UAC immediate customers are educated to note.<\/p>\n<p>The second blob decodes to a VBScript that deletes the registry key pointing to the installer and applies Safety Descriptor Definition Language (SDDL) strings and entry management lists that stop the service, put in beneath the disguised title \u201cHome windows Safety\u201d, from being seen, disabled, or eliminated, even by directors. The compromised host then reaches out to a command-and-control deal with within the United Arab Emirates over port 8041\/tcp.<\/p>\n<h4><strong>Detection and mitigation<\/strong><\/h4>\n<p>Huntress notes that the marketing campaign is detectable at its earliest stage: neither the sending area nor the embedded redirect hyperlink factors to Financial institution of America\u2019s real infrastructure, a discrepancy seen within the browser deal with bar earlier than any file is downloaded. The agency has revealed full indicators of compromise, together with the malicious domains, the C2 IP deal with, and file hashes, to its GitHub repository, and recommends organisations monitor for unauthorised ScreenConnect installations and strange SDDL\/ACL modifications on endpoint providers.<\/p>\n<p>The findings add to a rising physique of proof that RMM abuse stays a most well-liked approach for risk actors searching for persistent entry whereas evading conventional malware detection, notably when paired with brand-impersonation phishing that mimics a goal firm\u2019s visible identification carefully sufficient to go informal inspection.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Researchers at Huntress have recognized an energetic phishing marketing campaign impersonating Financial institution of America that culminates within the covert set up of a distant monitoring and administration (RMM) instrument, giving attackers persistent, hard-to-detect entry to victims\u2019 Home windows machines. The marketing campaign was flagged after a message landed in considered one of Huntress\u2019s spamtrap [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17431,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[3612,5798,210,3593,10033,2825,67,261,1538,894,10034],"class_list":["post-17429","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-america","tag-bank","tag-bypass","tag-delivering","tag-disguised","tag-emails","tag-fake","tag-phishing","tag-rat","tag-screenconnect","tag-uac"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17429","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17429"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17429\/revisions"}],"predecessor-version":[{"id":17430,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17429\/revisions\/17430"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17431"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-05 10:01:40 UTC -->