Overview
- Huntress captured the phishing email in a honeytrap on July 28 and published indicators and technical analysis after decoding a multi‑stage VBScript and PowerShell loader.
- The campaign fingerprints visitors so non‑Windows users see credential‑harvesting pages while Windows users are prompted to download a fake “Account Guard” that contains a trojanised ScreenConnect installer.
- The installer is delivered as a 17MB MSI downloaded from a public file‑sharing site and is decoded through nested Base64 and AES stages before execution.
- A decoded C# component uses the ICMLuaUtil Elevated COM interface to bypass User Account Control and install ScreenConnect with administrator privileges without prompting the user.
- After installation the actor deletes installer traces, registers the client as a benign‑looking service named “Windows Security,” modifies SDDL and ACLs to hide and block removal, and connects to a suspected C2 at 217.60.195.167; Huntress has posted IOCs and advises monitoring for unexpected ScreenConnect installs and atypical SDDL/ACL changes.