A phishing campaign targets financial institutions with emails that appear to be from Bank of America. The email prompts the recipient to visit a link, which delivers a Visual Basic script that decodes complex content and leads to the download of a ScreenConnect installer. When a Windows browser is used to visit the page, it instead prompts the reader to download and install Account Guard, which is actually a malicious payload.
The payload elevates its own privileges silently through the use of a C# script. The threat actor uses an unusual amount of embedded base64-encoded data blobs inside every script that runs a stage of the attack. This makes static scanning harder and slows down triage efforts. The final decoded version of the PowerShell script serves multiple purposes, including downloading a base64-encoded file in recent periods, then decoding the content to become a ScreenConnect installer.[/subscribe_to_unlock_form]
A phishing campaign targets financial institutions with emails that appear to be from Bank of America. The email prompts the recipient to visit a link, which delivers a Visual Basic script that decodes complex content and leads to the download of a ScreenConnect installer. When a Windows browser is used to visit the page, it instead prompts the reader to download and install Account Guard, which is actually a malicious payload.
The payload elevates its own privileges silently through the use of a C# script. The threat actor uses an unusual amount of embedded base64-encoded data blobs inside every script that runs a stage of the attack. This makes static scanning harder and slows down triage efforts. The final decoded version of the PowerShell script serves multiple purposes, including downloading a base64-encoded file in recent periods, then decoding the content to become a ScreenConnect installer.[emaillocker id="1283"]
The phishing campaign has been targeting victims using different types of devices. When a target visits the webpage from a Mac (or a browser that reports a non-Windows User-Agent), they are redirected to a conventional phishing page that asks for banking customer information. The actor's motivation and scale are unclear, but the campaign is significant due to its ability to evade detection and deliver malicious payloads.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1059.005 | Command and Scripting Interpreter | Visual Basic |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1027 | Obfuscated Files or Information | - |
| Defence Evasion | T1140 | Deobfuscate/Decode Files or Information | - |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]