IT Security Guru
Read post

Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass

Huntress researchers uncovered an active phishing campaign impersonating Bank of America that delivers a trojanized ScreenConnect RMM installer to Windows users. The attack chain uses a VBScript-triggered multi-stage base64 decoding process, a PowerShell script to fetch the installer, and AES-128-CBC-encrypted payloads. One payload exploits the ICMLuaUtil COM interface (MITRE ATT&CK T1548.002) to bypass UAC and install ScreenConnect with admin privileges silently. A second payload hides the service under the name 'Windows Security' using SDDL/ACL manipulation to prevent removal even by admins. The C2 server is located in the UAE on port 8041/tcp. Huntress has published full indicators of compromise and recommends monitoring for unauthorized ScreenConnect installs and unusual ACL changes.

    #malware#phishing
Aug 04•3m read time•From itsecurityguru.org
Post cover image
121 Impressions
IT Security Guru's image
IT Security Guru

IT Security Guru is a cybersecurity news portal offering articles, analysis, and insights on cyberse...

193 Followers

•

107 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard