Huntress researchers uncovered an active phishing campaign impersonating Bank of America that delivers a trojanized ScreenConnect RMM installer to Windows users. The attack chain uses a VBScript-triggered multi-stage base64 decoding process, a PowerShell script to fetch the installer, and AES-128-CBC-encrypted payloads. One payload exploits the ICMLuaUtil COM interface (MITRE ATT&CK T1548.002) to bypass UAC and install ScreenConnect with admin privileges silently. A second payload hides the service under the name 'Windows Security' using SDDL/ACL manipulation to prevent removal even by admins. The C2 server is located in the UAE on port 8041/tcp. Huntress has published full indicators of compromise and recommends monitoring for unauthorized ScreenConnect installs and unusual ACL changes.