Overview
- Huntress first caught the scam in a spam trap on July 28, when a spoofed Bank of America message redirected victims to attacker-controlled pages.
- The infrastructure fingerprints visitors so non-Windows users see credential‑harvesting forms while Windows users are prompted to download an "Account Guard" installer that is trojanised to deliver ScreenConnect.
- The payload uses a multi‑stage decode chain and a public ICMLuaUtil COM interface exploit to bypass User Account Control and run the installer with admin privileges.
- After installation the malware removes registry traces, registers ScreenConnect as a service named "Windows Security," and applies SDDL/ACL changes that block viewing, disabling, or uninstalling the tool; it then calls a C2 at 217.60.195[.]167 over TCP 8041.
- Huntress published domains, file hashes and the C2 IP on GitHub and recommends validating sender domains and links, blocking the listed hosts, and scanning for unauthorized ScreenConnect installs and unusual SDDL/ACL changes because abuse of legitimate RMM tools gives attackers stealthy, persistent access.