Phishing Campaign Mimics Bank of America to Install Remote Access Software
Cybercriminals have initiated a phishing campaign that closely mimics Bank of America, aiming to secretly install remote access software on targeted Windows computers. The emails, which replicate the bank’s branding, guide recipients through multiple fake websites before prompting them to download a file named Account Guard, as reported by Infosecurity Magazine.
When Windows users run this file, it triggers a multi-stage script that installs ScreenConnect remote monitoring software, disguised as a Windows Security service. The attackers utilize evasion tactics, including a User Account Control (UAC) bypass, to gain elevated privileges and connect the compromised system to a command-and-control server.
In contrast, Mac users receive prompts requesting personal information without any malware being delivered, indicating a device-specific design in the campaign. ScreenConnect is a legitimate remote management tool that is often exploited by threat actors for ongoing access after an initial compromise.
The phishing emails originated from a spoofed domain and were detected in a cybersecurity firm’s honeytrap account. Experts recommend that users carefully verify email senders and link destinations before clicking on any links.
FAQ
What is the purpose of the phishing campaign mimicking Bank of America?
The purpose of the phishing campaign is to secretly install remote access software on targeted Windows computers, allowing cybercriminals to gain control over the compromised systems.
How do the phishing emails trick users?
The phishing emails replicate Bank of America's branding and guide recipients through multiple fake websites before prompting them to download a malicious file named Account Guard.
What happens when a user runs the downloaded file?
When the file is run, it triggers a multi-stage script that installs ScreenConnect remote monitoring software, disguised as a Windows Security service, allowing attackers to gain elevated privileges.
Are Mac users affected by this phishing campaign?
Mac users receive prompts requesting personal information without any malware being delivered, indicating that the campaign is designed specifically for Windows users.
What precautions should users take to avoid falling victim to this phishing campaign?
Users should carefully verify email senders and link destinations before clicking on any links, and be cautious of unsolicited emails that ask for personal information or prompt downloads.
Comments
Comments are moderated before publish.
No comments yet — be the first.