What kind of malspam is "Bank Of America Account Update"
Phishing/ScamAlso Known As: Bank Of America Account Update malspam
Get free scan and check if your device is infected.
Remove it nowTo use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
What is the "Bank Of America Account Update" email virus?
We have analyzed this email and determined it is malspam. It impersonates Bank of America and falsely warns recipients that their account will be restricted unless they download and install a program called "Account Guard." That program is actually a remote access tool installed without the victim's knowledge, and the email should be ignored and deleted.

More about the "Bank Of America Account Update" email
The email presents itself as a final notice from Bank of America. It claims the recipient's account information was never confirmed after several requests and warns that the account will be restricted unless action is taken before August 17, 2026. A reference number is included to make the message appear official.
The link labeled "Visit the Security Center" does not lead to Bank of America. The page behind it checks which operating system the visitor is running and serves a different attack depending on the answer. Windows users are shown a fake Bank of America "Privacy & Security" page instructing them to install a program called "Account Guard," with a prominent "Update My Information" button prompting the download.
Clicking that button delivers a ZIP archive named AccountGuardSetup.zip. Inside is a Visual Basic Script file named AccountGuardSetup.vbs. Running that script activates multiple layers of hidden code that silently download a remote access program in the background.
As documented by Huntress, the script downloads and installs ScreenConnect - a legitimate remote monitoring and management tool - using a Windows privilege bypass to gain administrator access without any visible prompts. The installed software is registered under the name "Windows Security" to appear trustworthy.
Visitors using macOS are sent somewhere else entirely. Rather than a download, they are shown a counterfeit Bank of America online banking login page hosted on an unrelated domain. This is a phishing page, and anything typed into the User ID and Password fields is sent straight to the attackers.
Once running, ScreenConnect connects to an attacker-controlled server and gives cybercriminals full remote access to the computer. They can steal saved passwords, access banking accounts, install additional malware, or carry out fraudulent transactions. Bank of America has no connection to this campaign. Anyone who ran the file should disconnect from the internet, run a full antivirus scan, and contact their bank immediately.
| Name | Bank Of America Account Update malspam |
| Threat Type | Malspam, malicious spam, trojan, spyware, phishing. |
| Fake Claim | The recipient must confirm their Bank of America account information and install "Account Guard" to prevent account restrictions. |
| Disguise | Security alert from Bank of America. |
| Distributed Malicious File | AccountGuardSetup.zip (containing AccountGuardSetup.vbs) |
| Payload | Abused ScreenConnect (remote monitoring and management software used for unauthorized remote access) |
| Symptoms | Trojans are designed to stealthily infiltrate the victim's computer and remain silent, and thus no particular symptoms are clearly visible on an infected machine. |
| Distribution methods | Deceptive emails, social engineering. |
| Damage | Stolen passwords and banking information, identity theft, unauthorized remote access to the computer, financial losses. |
| Malware Removal (Windows) |
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. Download Combo CleanerTo use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com. |
Spam campaign examples
This campaign impersonates Bank of America to trick victims into running a malicious script that silently installs remote access software. Once that connection is established, attackers can fully control the infected computer without the victim's awareness. The email should be deleted without clicking any links.
FedEx Shipment Tracking Number Requires Information, DHL Express - Shipment Arrived, and Trip.com Booking Confirmation are just a few examples of similar malspam we have analyzed. Cybercriminals use spam emails to distribute a wide variety of malware types.
How do spam campaigns infect computers?
Spam emails spread malware through two main methods: malicious attachments and deceptive links. Attachments may look like ordinary documents, invoices, PDFs, or archives, but they can carry hidden malware. Clicking a link in a spam email can also lead to a fake page that serves a harmful file disguised as a legitimate program or security tool.
The type of file determines how the infection begins. Executable files infect a system almost immediately upon being opened. Script files, archives, and Office documents may require additional steps from the user - for example, Office files may need the user to enable macro commands before the malware activates.
How to avoid installation of malware?
Be cautious with unexpected emails, especially those urging urgent action regarding bank accounts or financial services. Do not click links or download programs delivered through email without independently verifying the sender. Legitimate banks do not ask customers to install security software by following email links.
Download software only from official websites or trusted sources. Keep your operating system and all installed programs up to date. Avoid pirated software, key generators, and unofficial patches, as these are frequently used to distribute malware.
Use a reputable antivirus program and run regular system scans. If you have already run files from suspicious emails, we recommend scanning with Combo Cleaner Antivirus for Windows to automatically eliminate any infiltrated malware.
Text presented in the "Bank Of America Account Update" email letter:
Subject: ⚠ Don't Lose Access – Complete Your Update Today (Ref. No: W7T9WWREZH)
BANK OF AMERICA
ACTION NEEDED: Update your profile to keep your account(s) open.
In previous emails, we informed you that your Bank of America account(s) information need to be confirmed. Your account information have not been confirmed within the set period, even after several requests.
To ensure uninterrupted access to our services, please update your account now or before August 17 2026.• You can find more detailed information on the actions you need to take by following [Visit the Security Center]
Since this requirement applies to your account(s), we need you to act quickly to avoid account restrictions.
We value your business and want to ensure you don't experience any interruption in your account services.[Online Privacy Policy] | [Member FDIC] | [Help & Support]
Please don't reply to this email because this mailbox isn't monitored.
Thank you for being a Bank of America client. You received this email as part of your existing relationship with us.
2026 Bank of America Corporation. All rights reserved.
Screenshot of the malicious website promoted by this spam campaign:

Fake Bank of America login page shown to macOS users:

Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
DOWNLOAD Combo CleanerBy downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quick menu:
- What is Bank Of America Account Update malspam?
- Types of malicious emails.
- How to spot a malicious email?
- What to do if you fell for an email scam?
Types of malicious emails:
Phishing Emails
Most commonly, cybercriminals use deceptive emails to trick Internet users into giving away their sensitive private information, for example, login information for various online services, email accounts, or online banking information.
Such attacks are called phishing. In a phishing attack, cybercriminals usually send an email message with some popular service logo (for example, Microsoft, DHL, Amazon, Netflix), create urgency (wrong shipping address, expired password, etc.), and place a link which they hope their potential victims will click on.
After clicking the link presented in such email message, victims are redirected to a fake website that looks identical or extremely similar to the original one. Victims are then asked to enter their password, credit card details, or some other information that gets stolen by cybercriminals.
Emails with Malicious Attachments
Another popular attack vector is email spam with malicious attachments that infect users' computers with malware. Malicious attachments usually carry trojans that are capable of stealing passwords, banking information, and other sensitive information.
In such attacks, cybercriminals' main goal is to trick their potential victims into opening an infected email attachment. To achieve this goal, email messages usually talk about recently received invoices, faxes, or voice messages.
If a potential victim falls for the lure and opens the attachment, their computers get infected, and cybercriminals can collect a lot of sensitive information.
While it's a more complicated method to steal personal information (spam filters and antivirus programs usually detect such attempts), if successful, cybercriminals can get a much wider array of data and can collect information for a long period of time.
Sextortion Emails
This is a type of phishing. In this case, users receive an email claiming that a cybercriminal could access the webcam of the potential victim and has a video recording of one's masturbation.
To get rid of the video, victims are asked to pay a ransom (usually using Bitcoin or another cryptocurrency). Nevertheless, all of these claims are false - users who receive such emails should ignore and delete them.
How to spot a malicious email?
While cyber criminals try to make their lure emails look trustworthy, here are some things that you should look for when trying to spot a phishing email:
- Check the sender's ("from") email address: Hover your mouse over the "from" address and check if it's legitimate. For example, if you received an email from Microsoft, be sure to check if the email address is @microsoft.com and not something suspicious like @m1crosoft.com, @microsfot.com, @account-security-noreply.com, etc.
- Check for generic greetings: If the greeting in the email is "Dear user", "Dear @youremail.com", "Dear valued customer", this should raise suspiciousness. Most commonly, companies call you by your name. Lack of this information could signal a phishing attempt.
- Check the links in the email: Hover your mouse over the link presented in the email, if the link that appears seems suspicious, don't click it. For example, if you received an email from Microsoft and the link in the email shows that it will go to firebasestorage.googleapis.com/v0... you shouldn't trust it. It's best not to click any links in the emails but to visit the company website that sent you the email in the first place.
- Don't blindly trust email attachments: Most commonly, legitimate companies will ask you to log in to their website and to view any documents there; if you received an email with an attachment, it's a good idea to scan it with an antivirus application. Infected email attachments are a common attack vector used by cybercriminals.
To minimise the risk of opening phishing and malicious emails we recommend using Combo Cleaner Antivirus for Windows.
Example of a spam email:

What to do if you fell for an email scam?
- If you clicked on a link in a phishing email and entered your password - be sure to change your password as soon as possible. Usually, cybercriminals collect stolen credentials and then sell them to other groups that use them for malicious purposes. If you change your password in a timely manner, there's a chance that criminals won't have enough time to do any damage.
- If you entered your credit card information - contact your bank as soon as possible and explain the situation. There's a good chance that you will need to cancel your compromised credit card and get a new one.
- If you see any signs of identity theft - you should immediately contact the Federal Trade Commission. This institution will collect information about your situation and create a personal recovery plan.
- If you opened a malicious attachment - your computer is probably infected, you should scan it with a reputable antivirus application. For this purpose, we recommend using Combo Cleaner Antivirus for Windows.
- Help other Internet users - report phishing emails to Anti-Phishing Working Group, FBI’s Internet Crime Complaint Center, National Fraud Information Center and U.S. Department of Justice.
Frequently Asked Questions (FAQ)
Why did I receive this email?
Cybercriminals send identical spam messages to large numbers of people at once. These emails are not personally targeted. Recipient addresses are typically gathered through data breaches, purchased lists, or other means.
I have provided my personal information when tricked by this email, what should I do?
If you entered banking credentials or personal information, contact your bank immediately to secure your account. Change passwords for any accounts that may have been exposed, and report the incident to the relevant authorities.
I have downloaded and run a file promoted by a link in this spam email, is my computer infected?
If you ran the VBScript file, your computer is very likely infected. The script silently installs remote access software that gives attackers control over your system. Disconnect from the internet and run a full antivirus scan right away.
I have read the email but did not click any links, is my computer infected?
No. Simply reading an email cannot infect your computer. Infection only occurs if you click a link, download a file, and then run it. No interaction with the email content means no risk.
Will Combo Cleaner remove malware installed through files distributed via spam email links?
Yes, Combo Cleaner is capable of detecting and removing most known malware, including remote access tools installed without user consent. Running a complete system scan is strongly recommended to ensure nothing remains hidden.
Share:
Tomas Meskauskas
Expert security researcher, professional malware analyst
I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion