Fake Bank of America Email Pushes Remote Access Tool

Infosecurity Magazine · Medium sophistication
Last updated August 5, 2026

Cybercriminals sent emails styled like Bank of America that redirected victims to fake pages and pushed a download called “Account Guard.” On Windows, the download installed ScreenConnect remote management software, giving attackers remote control of the device. The campaign used lookalike domains and a multi-step script chain to hide what it was doing.

Key findings

  • Phishing emails impersonated Bank of America branding and directed users to a fake “Security Centre.”
  • The email chain led Windows users to download and install a fake protection tool called “Account Guard.”
  • Clicking “Update My Information” delivered AccountGuardSetup.zip containing a .vbs script that ultimately installed ScreenConnect (remote management software).
  • Different experiences were served by device type: Mac users were prompted to submit “valuable personal information,” while Windows users were pushed to install software.
  • The campaign used lookalike domains (e.g., bkofamerica[.]com) and multiple redirect domains (kleinschnitg[.]com, sectioncompil[.]com).
  • After installation, ScreenConnect connected to a suspected C2 at 217.60.195[.]167 on TCP port 8041 and waited for commands.
  • Huntress advised focusing on the sender and link destinations as a primary mitigation.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance/Accounting, IT helpdesk/service desk.
  • Affected industries: Finance/Banking, Consumers/Individual users.
  • Attack channels: email, website.
  • Impersonated: Bank of America.

Awareness takeaways

  • Train staff to hover/check links and verify the real domain before clicking, especially for banking or “security center” messages.
  • Treat unexpected “security software” downloads from emails or web pages as a major red flag; do not install tools unless IT/security approved.
  • Coach users to be suspicious of ZIP files and script files (like .vbs) coming from the web, these are common ways attackers start an infection chain.
  • Remind users that scams may show different content depending on device (Mac vs Windows), so reporting suspicious pages still matters even if nothing downloads.

Red flags to watch for

  • Lookalike domains (not the real bank domain)
  • Security tool download offered from a bank-branded webpage
  • Unexpected ZIP download containing a script file (.vbs)
  • Pressure to install software from a bank website (banks typically do not distribute endpoint installers this way)
  • Download is a ZIP containing a script (.vbs)
  • The button name (“Update My Information”) does not match the action (software installation)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email that looks like Bank of America, warning: “Visit our Security Centre to protect your account.” You click. The “Security Centre” page looks bank-branded, but the address bar says bkofamerica.com and random redirects like kleinschnitg.com flash by. On Windows, the page pushes a tool called “Account Guard.” You click “Update My Information” and instead get AccountGuardSetup.zip with a .vbs script that secretly installs ScreenConnect remote control. Here’s the move: before you click any bank “Security Centre” link, hover and read the domain. If it’s not the exact bank site you expect, close it and report it to IT.

Similar attacks

Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026
Fake ScreenConnect Installs Spread Like a Worm

Fake ScreenConnect Installs Spread Like a Worm

Huntress reported real-world attacks where criminals used social engineering to get victims to install or run remote support tools, then deployed modified (rogue) ScreenConnect clients. After gaining control, the attackers ran scripts to recon the system, stage additional payloads, and spread the…

September 7, 2026
“Case Documents” Lure Hits Law Firm via LNK

“Case Documents” Lure Hits Law Firm via LNK

Researchers reported a real spear‑phishing intrusion against a law firm where attackers sent a message with a link to an encrypted archive. The archive contained a Windows shortcut (LNK) disguised as “Case Documents,” and running it launched a multi‑stage loader (“HollowFrame”) that ultimately…

July 31, 2026
ClickFix Lures Spread ChainScript RAT

ClickFix Lures Spread ChainScript RAT

Researchers describe real-world “ClickFix” social-engineering lures that trick people into installing malware by downloading fake apps (like Spotify/Zoom/Teams) or copying commands into Terminal. One campaign abused a compromised, verified HBO Max Reddit account to run malicious ads, while another…

September 21, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026