Threat Advisory

Bank of America Phishing Email Delivers Visual Basic Script

Threat: Phishing Campaign
Targeted Region: Global
Targeted Sector: Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A phishing campaign targets financial institutions with emails that appear to be from Bank of America. The email prompts the recipient to visit a link, which delivers a Visual Basic script that decodes complex content and leads to the download of a ScreenConnect installer. When a Windows browser is used to visit the page, it instead prompts the reader to download and install Account Guard, which is actually a malicious payload.

The payload elevates its own privileges silently through the use of a C# script. The threat actor uses an unusual amount of embedded base64-encoded data blobs inside every script that runs a stage of the attack. This makes static scanning harder and slows down triage efforts. The final decoded version of the PowerShell script serves multiple purposes, including downloading a base64-encoded file in recent periods, then decoding the content to become a ScreenConnect installer.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A phishing campaign targets financial institutions with emails that appear to be from Bank of America. The email prompts the recipient to visit a link, which delivers a Visual Basic script that decodes complex content and leads to the download of a ScreenConnect installer. When a Windows browser is used to visit the page, it instead prompts the reader to download and install Account Guard, which is actually a malicious payload.

The payload elevates its own privileges silently through the use of a C# script. The threat actor uses an unusual amount of embedded base64-encoded data blobs inside every script that runs a stage of the attack. This makes static scanning harder and slows down triage efforts. The final decoded version of the PowerShell script serves multiple purposes, including downloading a base64-encoded file in recent periods, then decoding the content to become a ScreenConnect installer.[emaillocker id="1283"]

The phishing campaign has been targeting victims using different types of devices. When a target visits the webpage from a Mac (or a browser that reports a non-Windows User-Agent), they are redirected to a conventional phishing page that asks for banking customer information. The actor's motivation and scale are unclear, but the campaign is significant due to its ability to evade detection and deliver malicious payloads.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1059.005 Command and Scripting Interpreter Visual Basic
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027 Obfuscated Files or Information -
Defence Evasion T1140 Deobfuscate/Decode Files or Information -
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu