Hackers abuse Faronics Deploy admin tool to install ScreenConnect

A Sneaky Phishing Campaign Exploits Faronics Deploy Platform, Installs Malicious ScreenConnect Software

Phishing actors have been using a legitimate endpoint management platform to gain remote control over victim computers and install malicious software. The attackers are abusing the cloud-based Faronics Deploy platform, which is designed for IT administrators to manage and deploy software remotely. By disguising their malicious links as legitimate invoices or business files, they’ve reached over 457 endpoints between July 21 and August 20.

Faronics Deploy allows administrators to enroll computers, deploy software, and execute scripts remotely. However, the attackers have embedded malicious links in these emails that lead potential victims to a website profiling them and guiding them through a download flow. If accessed from an analysis environment, the site displays a decoy error message. The attackers then prompt victims to download and launch a legitimate Faronics Deploy installer, often disguised as Adobe software or a plugin update.

When the victim runs this installer, their computer is enrolled in a Faronics deployment controlled by the attackers. These malicious actors use Faronics’ remote-deployment functionality to execute PowerShell scripts on the enrolled computers without further user interaction. The scripts download additional tools from attacker-controlled infrastructure, including GitHub, eventually installing the ConnectWise ScreenConnect remote access tool.

The installation of ScreenConnect provides attackers with an additional channel for remote access, independent of Faronics. This gives them hands-on control and redundancy in case their malicious deployment is identified or removed. Huntress, a managed detection and response company, notified Faronics about the issue on August 5, and the vendor confirmed the activity. Faronics subsequently implemented anti-abuse measures and contacted affected organizations to notify them of potential compromise.

The malicious activity dropped significantly starting August 21, indicating that these measures were effective. However, Huntress recommends that administrators check for a ScriptRunner.log file in the “C:\ProgramData\Faronics\Logs\” location, which may preserve remotely executed script names and download URLs. They should also look for ScreenConnect installations where it’s not normally deployed.

In an age of increasingly sophisticated phishing campaigns, this incident highlights the importance of staying vigilant and regularly monitoring endpoint activity. By recognizing indicators like unusual Faronics configuration requests or ScreenConnect installations, administrators can take proactive measures to prevent further compromise.


Source: Bleeping Computer — 2026-09-01