Bank Impersonation Phish Pushes Remote Tool

About DFIR · Medium sophistication
Last updated August 7, 2026

A real, active phishing campaign impersonating Bank of America tricks victims into downloading a fake “Account Guard” that installs ScreenConnect remote access on Windows, while Mac users are redirected to a credential-stealing page asking for banking and identity details. Separately, Microsoft described a macOS “ClickFix” campaign that uses cloaked fake download sites to lure users into copying and running a Terminal command that installs infostealer malware.

How the attack worked

This campaign impersonates Bank of America to push a fake security download called Account Guard. Windows users who download and run it get ScreenConnect remote access software disguised as a Windows Security service. The tool is set up with layered permission changes that block the victim from viewing or uninstalling it through normal tools like services.msc or Get-Service, making cleanup harder for the average user.

Mac users who click the same phishing link are not sent down the remote-access path. Instead they land on a credential-harvesting page that requests their banking login details plus full personal and financial information, including government ID and Social Security numbers. This split by operating system shows the attacker adapting the payload to what will actually work on each platform.

A related but separate campaign, described by Microsoft, targets macOS users through fake software download sites. These sites fingerprint visitors before deciding whether to serve a malicious page, hiding it from crawlers, sandboxes, and non-Mac visitors. Qualifying targets see a convincing fake Download for macOS page complete with a forged verified-publisher badge, then are told to copy and run an obfuscated Terminal command. That command results in infection with MacSync or Atomic Stealer.

Why it succeeded

Brand impersonation of a trusted bank lowers suspicion, and the campaign is assessed as a broad, untargeted blast rather than a spear-phishing operation, meaning it relies on volume rather than precision targeting. The use of a fake verified-publisher badge and legitimate-sounding names like Account Guard and Windows Security adds a layer of visual trust that many users will not question.

What to watch for

  • Unexpected security software download prompts arriving by email, especially ones claiming to be from a bank
  • Requests for highly sensitive identity data, like SSNs or government ID, tied to a routine account verification
  • Web pages that instruct you to open Terminal and paste in a command to finish installing something
  • Trust badges or verified-publisher labels on unfamiliar download pages

Building resistance

Teams should verify unexpected security tool requests through official banking channels rather than clicking email links. Sensitive identity data should never be submitted through a form linked from an unsolicited email without independent confirmation. IT and developer staff, who are more comfortable using command-line tools, should be reminded that legitimate software installs rarely require copying and pasting a Terminal command from a website, and that verified-publisher badges can be forged.

Key findings

  • An active phishing campaign impersonates Bank of America and pushes victims to a fake “Account Guard” download.
  • On Windows, the download installs ScreenConnect remote access, disguised as a “Windows Security” service, and is made difficult to remove via normal tools.
  • On macOS, victims are redirected to a credential-harvesting page requesting banking logins plus personal/financial information including government ID and Social Security numbers.
  • Microsoft described a macOS ClickFix campaign using many rotating “download” domains that fingerprint visitors and show a fake “Download for macOS” page with a forged verified-publisher badge.
  • ClickFix victims are instructed to copy/run an obfuscated Terminal command, resulting in infostealer infections (MacSync or Atomic Stealer/AMOS).

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Executives, IT, Developers, Customer support.
  • Affected industries: Finance and banking, Consumers/retail banking customers, Technology (macOS endpoints), General business users (Windows endpoints).
  • Attack channels: email, website.
  • Impersonated: Bank of America, Software download site / verified publisher.

Red flags to watch for

  • Unexpected security software download pushed via email
  • Brand impersonation (bank look-and-feel, but nonstandard install flow)
  • Pressure to install a tool that enables remote access
  • Sensitive identity requests that go beyond normal login (ID/SSN)
  • Email drives to a web form for highly sensitive data
  • Mismatch between device type and what the page requests (different flows for Mac/Windows)
  • Website instructs running Terminal commands to install software
  • “Verified”/trust badges that may be forged
  • Download pages that appear only after device ‘checks’ (fingerprinting)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the fake Account Guard phishing campaign?

It is an active phishing campaign impersonating Bank of America that pushes Windows users toward a fake Account Guard download which actually installs the ScreenConnect remote access tool disguised as a Windows Security service.

What happens to Mac users who click the same phishing link?

Mac users are instead directed to a credential-harvesting page requesting banking login details along with full personal and financial information, including government ID and Social Security numbers.

What is the separate ClickFix campaign mentioned alongside this?

Microsoft described a macOS ClickFix campaign that uses rotating fake download domains and a forged verified-publisher badge to trick users into copying and running a Terminal command that installs infostealer malware.

Why is running a Terminal command from a website risky?

Victims who copy and run the obfuscated Terminal command are ultimately infected with MacSync or Atomic Stealer, so any site asking users to paste commands into Terminal should be treated as suspicious.

Read the video transcript

You get an email: “Your Bank of America account needs ‘Account Guard’ protection, download now.” Looks urgent, looks legit. Click it on Windows, and that “Account Guard” quietly installs ScreenConnect remote access, disguised as a Windows Security service that barely shows up and is hard to remove. On macOS, the same email can send you to a fake Bank of America page asking for your banking login, government ID, and Social Security number, or a “Download for macOS” page with a forged verified-publisher badge telling you to copy a weird Terminal command. If any “bank” email tells you to install protection software or run a Terminal command, stop, go to the bank’s website or app yourself and check from there.

Similar attacks

Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026
Hotel Wi‑Fi Hijack Pushes Fake Updates & Phishing

Hotel Wi‑Fi Hijack Pushes Fake Updates & Phishing

Microsoft reported a campaign where attackers abused hotel Wi‑Fi captive portals to manipulate DNS/HTTP traffic and redirect people to attacker-controlled phishing pages. Victims were tricked into installing malware disguised as browser/operating system updates, and some pages redirected users into…

August 3, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
Fake Claude Download Page Led to SectopRAT

Fake Claude Download Page Led to SectopRAT

Attackers abused Anthropic’s Claude “Artifacts” publishing feature to host a convincing fake Claude download page on the real claude.ai domain. Victims found it via a sponsored Bing ad, clicked “Download,” and were redirected to attacker-controlled sites that delivered the SectopRAT remote access…

July 23, 2026
Consent Phishing and Hijacked Hotel Wi‑Fi Portals

Consent Phishing and Hijacked Hotel Wi‑Fi Portals

This weekly threat bulletin summarizes multiple real-world incidents, including phishing that abuses Microsoft’s legitimate app login/consent screens and a campaign that hijacks hotel Wi‑Fi captive portals. In both cases, the goal is to trick people into granting access or capturing Microsoft…

August 3, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026