Share
BANK IMPERSONATION - REMOTE ACCESS MALWARE

The email offered Bank of America security software. It installed remote control.

A message that reached a security firm's trap account on 28 July asked for no password and showed no login form. It offered a free protection tool called Account Guard. Running it handed someone else a live view of the screen and the use of the machine.

SafeBrowz Threat Research Security Research · · 9 min read

What this email actually does

Bank of America really does offer customers free security software, and that is exactly why this works: the email copies the idea and offers a free tool it calls Account Guard. The file is not from the bank. On Windows it installs remote access software, so a stranger can watch the screen and use the computer; on a phone, a Mac or Linux the same page asks for your banking login and then for your Social Security number and card details instead. The check that holds is where the link goes rather than what the message says, and a quick run through a checker settles that faster than reading it, because the sending domain here is a shortened copy of the bank's real one that survives a glance.

SafeBrowz judges the page a link opens, before you decide whether to trust what is on it. Add to Chrome, free Get the free Android app or scan a URL now →

What arrived on 28 July

The message landed in a trap account run by the security firm Huntress, whose researcher Andrew Brandt published the analysis on 4 August 2026; Infosecurity Magazine reported it the following day. The email imitated Bank of America's visual style, layout and branding, and it kept doing so through every step that followed, right down to the final web page.

What it did not contain is the thing most people are watching for. There was no login box, no request for a card number, nothing to fill in. The message simply pointed the reader at what it called the bank's Security Center. That absence is the reason it works on someone who has learned to be careful about typing passwords into emailed forms. Nothing is being asked for, so nothing feels risky.

This is a different mechanism from the fraud alert texts that use the same brand, which we cover in the Bank of America fraud alert text scam. Those want your credentials. This one wants your computer, and if it cannot have that it takes the credentials anyway.

Where the links actually went

The email came from bkofamerica[.]com, not from the bank. The real address is bankofamerica.com, and the difference is two letters removed from the middle of a word most people read as a shape rather than a spelling. Shortening bank to bk is an old trick precisely because it does not look like a misspelling. It looks like an abbreviation a large company might reasonably use.

The link inside the message went somewhere else again, to kleinschnitg[.]com, which opened a page hosted on sectioncompil[.]com, and that is where the download came from. Three separate addresses for one email is not overengineering. Each hop can be replaced independently when it gets blocked, so losing the download host does not cost the attacker the email campaign, and losing the sending domain does not cost them the page.

All three of those addresses are in our blocklist as of today, so a click on any of them is stopped rather than followed. That is worth stating plainly because it is the narrow claim: those three are blocked, and the next three the same group registers will not be until someone finds them.

Account Guard is the lure, not the payload

The page described Account Guard as "a powerful tool designed to protect your financial data, prevent unauthorized transactions, and other cyber threats". It is a good sentence. It is what you would want a bank to offer you, written the way a bank would write it, and it inverts the usual instinct: the reader is not being asked to hand something over, they are being offered protection.

Clicking Update My Information delivered a file called AccountGuardSetup.zip. Inside was a script, AccountGuardSetup.vbs, and running that started a chain of steps that each decoded the next one, ending in a download of roughly 17MB from a file hosting service, which unpacked into an installer for ScreenConnect.

ScreenConnect is real software. IT departments use it to take control of a computer they are supporting, with permission. That is the whole point of choosing it: there is no suspicious homemade program to find, because the program is a legitimate commercial product doing exactly what it was built to do, for someone who was never invited. The install then named itself after a Windows security service and cleaned up the traces of how it arrived, and it raised its own privileges without showing the permission prompt a user would normally see and question.

The same shape shows up in fake Zoom and Teams update prompts, where the download is framed as maintenance rather than protection. The framing changes; the request to run a file does not.

On a phone or a Mac, the same page asks for something else

The researchers found the campaign checked what the visitor was using. A Windows browser was offered the installer. Anything reporting itself as something else, which covers a Mac but equally an iPhone, an Android phone or Linux, was sent down a second path with no download in it at all: a conventional sign-in page asking for the banking username and password, entered twice behind a faked error, and then a further page asking for the full name and mailing address, government ID details, Social Security number and payment card details.

That detail matters for a reason that has nothing to do with which device you own. It means "nothing downloaded" is not the same as "nothing happened", and on a phone it is the likelier outcome. Someone who reached that page and filled it in has handed over more than a password: an identity file complete enough to open credit in their name, with no file on disk afterwards to point at as evidence that anything went wrong.

Why remote access is worse than a stolen password

A stolen password is a bad afternoon. You change it, you check the statements, you move on. Remote control of the machine is a different category of problem, and it is worth being clear about why.

Someone operating your computer does not need your banking password, because your browser is already signed in. They do not need to defeat two factor authentication, because the code arrives on your phone and you are the one who reads it out when a convincing voice on the phone asks. They do not need to hide their location, because the bank sees your device, at your address, on your usual network. Everything that normally protects an account is working perfectly and pointing the wrong way.

They also have the files, the saved logins in the browser, and the email account that resets everything else. If this has already happened to you, our guide on what to do after a scam covers the order to do things in, and disconnecting the machine comes before anything else.

Thirty seconds that would have stopped this

Not a long checklist, because a long checklist does not get used on a Tuesday morning. Four things, in the order they are quickest to check.

  • Get software from the bank, never from the message. Banks do offer real security tools, and this campaign is built on that fact, so "my bank would never send software" is the wrong rule and will fail you. The right one is that you go to the bank's own site and find it there yourself. A download that only exists inside an email is the problem, not the software.
  • Read the domain as letters, not as a shape. Your eye reads bkofamerica as the bank because it starts and ends correctly. Spell it out. If you find yourself squinting, that is the answer.
  • Check where the link goes before it goes there. Copy the link rather than clicking it, and paste it into a checker. This is the step that handles the case where the address looks fine and is not, which is the case this campaign was built around.
  • Reach the bank the way you already do. The app, a bookmark, or the number on the back of your card. A real alert will be waiting for you there, and a fake one will not exist.

The same logic applies to any sender you are unsure of; checking whether an email address is real walks through the general version, and fake login pop-ups on trusted sites covers the variant that never leaves the page you were already on.

Blocking the download before the script runs

This campaign is easy to stop and hard to notice, which is an uncomfortable combination. Every dangerous moment in it is a click, and all of them happen before any file exists on the computer.

SafeBrowz works in three layers. Layer 1 runs in the browser itself and reads the shape of the address, a list of suspicious keyword and urgency phrases, and homoglyph tricks, with no network call. Layer 2 is the server side: reputation feeds, our brand database of over 550 names, and our own blocklist, which is where the three addresses from this campaign now sit. Layer 3 runs AI content analysis on what the page actually serves, which is the layer built for a page with no history, since a fresh address is not in anyone's reputation data on its first day.

Honest scope, and it is the important part here. We judge links and pages. We do not scan a file that is already on your disk, and we cannot stop a script that is already running. If you have run this installer, no browser tool is the right answer any more, and the disconnect-and-call-the-bank steps in the questions below matter more than anything we do.

Paste a link from a message that says it is your bank, before you open it. Check a URL free → Get the free Android app
🛡 LIVE CHECK

Not sure where an email link goes?

Paste it here instead of clicking it. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

Is the Bank of America Account Guard email real?

No. There is no Bank of America product called Account Guard, and the file it offers installs remote access software. What makes the lure effective is that the underlying idea is true: Bank of America does offer customers free fraud protection software, so an email offering exactly that does not sound absurd. The difference is where it comes from. Real security software is found on the bank's own site, by going there yourself. This one exists only inside an email.

What is ScreenConnect and why was it installed?

ScreenConnect is a legitimate commercial remote support product that IT teams use to operate computers they are helping. It is not malware, which is why attackers reach for it: it is real software doing exactly what it was built to do, for someone who was never invited. In this campaign it arrived through several layers of encoded script, which the researchers noted was done to make the files harder to inspect.

I clicked the link but did not open the file. Am I affected?

Visiting the page alone does not install anything; the installation needs you to open the downloaded archive and run the script inside it. Delete the download and change your online banking password from a device you trust. If you were on a phone, a Mac or Linux you would not have been offered a file at all, so the question is different: did you type anything in? If you entered your banking login, treat it as compromised. If you gave the Social Security number, ID or card details the second page asks for, replace the card and consider a credit freeze, because that combination is enough to open accounts in your name.

I ran the installer. What should I do now?

Disconnect the computer from the internet first, because remote access only works while it is online. Then call Bank of America on the number printed on your card, never a number from the email, and tell them the machine may be compromised. Do not expect to remove this yourself: the researchers found the install was configured to stay out of the installed applications list and to resist normal removal, so it needs someone who can examine the machine properly. Change your passwords from a different device in the meantime, not from that one.

How do I tell a real bank email from this one?

Judge the address the link opens rather than the branding in the message, because the branding is copied perfectly and the address cannot be. In this campaign the sending domain was a shortened spelling of the bank's real one, which reads as correct at a glance, so if you do have to judge a link rather than ignore it, paste the address into a scam checker instead of trusting the reading. The safe habit is to ignore the link entirely and reach your bank the way you normally do, through the app or a typed address.

Follow on Google