A phishing campaign impersonating Bank of America is targeting victims with different payloads based on device type. Huntress reported that non-Windows users are redirected to credential-harvesting pages that solicit usernames, passwords, personally identifiable information, Social Security numbers, government ID details, and payment card data, while Windows users are lured into downloading a fake "Account Guard" installer presented as a ZIP file.
On Windows systems, the installer launches a multi-stage infection chain using VBScript and layered Base64-decoded PowerShell to download and silently install ScreenConnect for persistent remote access. The malware abuses the ICMLuaUtil elevated COM interface to bypass UAC and gain administrator privileges without prompting the user, then hides itself as a "Windows Security" service, alters uninstall visibility, and modifies SDDL and ACL settings to hinder removal. Huntress linked the activity to domains including bkofamerica[.]com, kleinschnitg[.]com, and sectioncompil[.]com, and said the ScreenConnect implant communicated with 217.60.195[.]167 over TCP port 8041.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Huntress detected the campaign after a phishing message impersonating Bank of America reached one of its honeytrap/spamtrap accounts. The email used a spoofed sender and a time-sensitive account confirmation lure to pressure recipients into clicking.
Huntress released indicators of compromise for the campaign, including malicious domains, the command-and-control IP address, and file hashes tied to the phishing and malware stages. The published IOCs covered artifacts such as the fake installer archive, scripts, and ScreenConnect payloads.
Huntress analyzed the campaign and found that non-Windows visitors were redirected to credential-harvesting pages, while Windows users were served a fake "Account Guard" download that launched a multi-stage infection chain. The Windows path installed ScreenConnect with an ICMLuaUtil COM-based UAC bypass, disguised the service as "Windows Security," and used SDDL/ACL changes to hinder detection and removal.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceinfosecurity-magazine.com
Open sourceitsecurityguru.org
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.