Fake Bank of America Email Pushes Remote Access Tool

Infosecurity Magazine · Medium sophistication
Last updated August 5, 2026

Cybercriminals sent emails styled like Bank of America that redirected victims to fake pages and pushed a download called “Account Guard.” On Windows, the download installed ScreenConnect remote management software, giving attackers remote control of the device. The campaign used lookalike domains and a multi-step script chain to hide what it was doing.

Key findings

  • Phishing emails impersonated Bank of America branding and directed users to a fake “Security Centre.”
  • The email chain led Windows users to download and install a fake protection tool called “Account Guard.”
  • Clicking “Update My Information” delivered AccountGuardSetup.zip containing a .vbs script that ultimately installed ScreenConnect (remote management software).
  • Different experiences were served by device type: Mac users were prompted to submit “valuable personal information,” while Windows users were pushed to install software.
  • The campaign used lookalike domains (e.g., bkofamerica[.]com) and multiple redirect domains (kleinschnitg[.]com, sectioncompil[.]com).
  • After installation, ScreenConnect connected to a suspected C2 at 217.60.195[.]167 on TCP port 8041 and waited for commands.
  • Huntress advised focusing on the sender and link destinations as a primary mitigation.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance/Accounting, IT helpdesk/service desk.
  • Affected industries: Finance/Banking, Consumers/Individual users.
  • Attack channels: email, website.
  • Impersonated: Bank of America.

Awareness takeaways

  • Train staff to hover/check links and verify the real domain before clicking, especially for banking or “security center” messages.
  • Treat unexpected “security software” downloads from emails or web pages as a major red flag; do not install tools unless IT/security approved.
  • Coach users to be suspicious of ZIP files and script files (like .vbs) coming from the web, these are common ways attackers start an infection chain.
  • Remind users that scams may show different content depending on device (Mac vs Windows), so reporting suspicious pages still matters even if nothing downloads.

Red flags to watch for

  • Lookalike domains (not the real bank domain)
  • Security tool download offered from a bank-branded webpage
  • Unexpected ZIP download containing a script file (.vbs)
  • Pressure to install software from a bank website (banks typically do not distribute endpoint installers this way)
  • Download is a ZIP containing a script (.vbs)
  • The button name (“Update My Information”) does not match the action (software installation)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email that looks like Bank of America, warning: “Visit our Security Centre to protect your account.” You click. The “Security Centre” page looks bank-branded, but the address bar says bkofamerica.com and random redirects like kleinschnitg.com flash by. On Windows, the page pushes a tool called “Account Guard.” You click “Update My Information” and instead get AccountGuardSetup.zip with a .vbs script that secretly installs ScreenConnect remote control. Here’s the move: before you click any bank “Security Centre” link, hover and read the domain. If it’s not the exact bank site you expect, close it and report it to IT.

Similar attacks

Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026
Fake ScreenConnect Installs Spread Like a Worm

Fake ScreenConnect Installs Spread Like a Worm

Huntress reported real-world attacks where criminals used social engineering to get victims to install or run remote support tools, then deployed modified (rogue) ScreenConnect clients. After gaining control, the attackers ran scripts to recon the system, stage additional payloads, and spread the…

September 7, 2026
“Case Documents” Lure Hits Law Firm via LNK

“Case Documents” Lure Hits Law Firm via LNK

Researchers reported a real spear‑phishing intrusion against a law firm where attackers sent a message with a link to an encrypted archive. The archive contained a Windows shortcut (LNK) disguised as “Case Documents,” and running it launched a multi‑stage loader (“HollowFrame”) that ultimately…

July 31, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026
Voucher Lure Drops RAT via FTP Banner Tricks

Voucher Lure Drops RAT via FTP Banner Tricks

Researchers reported a real malware campaign where attackers use Spanish-language “voucher claim” messages to trick people into running a Windows Shortcut file. After the user clicks it, the malware pulls commands from an FTP server’s welcome banner and continues downloading additional payloads,…

August 25, 2026