Particle.news
Download on the App Store

Phishing Campaign Posing as Bank of America Installs Trojanised ScreenConnect with Silent UAC Bypass

Huntress says the attack fingerprints devices, escalates privileges with an ICMLuaUtil exploit, and alters service SDDL and ACLs to hide long‑term remote access.

Overview

  • Huntress captured the phishing email in a honeytrap on July 28 and published indicators and technical analysis after decoding a multi‑stage VBScript and PowerShell loader.
  • The campaign fingerprints visitors so non‑Windows users see credential‑harvesting pages while Windows users are prompted to download a fake “Account Guard” that contains a trojanised ScreenConnect installer.
  • The installer is delivered as a 17MB MSI downloaded from a public file‑sharing site and is decoded through nested Base64 and AES stages before execution.
  • A decoded C# component uses the ICMLuaUtil Elevated COM interface to bypass User Account Control and install ScreenConnect with administrator privileges without prompting the user.
  • After installation the actor deletes installer traces, registers the client as a benign‑looking service named “Windows Security,” modifies SDDL and ACLs to hide and block removal, and connects to a suspected C2 at 217.60.195.167; Huntress has posted IOCs and advises monitoring for unexpected ScreenConnect installs and atypical SDDL/ACL changes.