Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Cyberattackers Exploit Faronics Deploy to Install Malicious Remote Access Tool

A sophisticated phishing campaign has been discovered abusing a legitimate endpoint management platform, Faronics Deploy, to gain unauthorized access to victim computers and install a remote support software. Researchers at Huntress, a managed detection and response company, uncovered the scheme, which targeted over 457 endpoints between July 21 and August 20.

The attackers used phishing emails disguised as invoices, tax documents, or other business files to trick victims into downloading and launching a Faronics Deploy installer. The installer was masqueraded as an Adobe document, a reader app, or a plugin update, making it difficult for users to distinguish between legitimate and malicious activity.

Once installed, the attackers used Faronics’ remote-deployment functionality to execute PowerShell scripts on the compromised computer without further user interaction. These scripts downloaded additional tools from the attacker’s infrastructure or external locations, including GitHub, eventually installing another legitimate remote access tool, ConnectWise ScreenConnect.

The use of ScreenConnect provides attackers with an additional remote-access channel independent of Faronics, allowing for hands-on remote control and serving as redundancy if the malicious Faronics deployment is identified and terminated. This allows attackers to maintain control even if their initial vector is detected.

Faronics was notified by Huntress on August 5, and the vendor confirmed the observed malicious activity, implementing additional anti-abuse measures shortly after. The company also contacted victimized organizations to notify them about potential compromise. According to Huntress, the malicious activity dropped significantly starting August 21, indicating that Faronics’ actions were effective.

To help administrators identify compromised endpoints or malicious accounts, Huntress recommends checking the “C:\ProgramData\Faronics\Logs\” location for a ScriptRunner.log file, which may preserve remotely executed script names and download URLs. Additionally, administrators should look for ScreenConnect installations where it is not normally deployed.

This attack serves as a reminder of the importance of vigilance in endpoint management. Even with robust security measures in place, attackers can still find ways to exploit legitimate tools. As Huntress’ findings demonstrate, prevention scores can hide what happens after initial access, and once attackers have valid credentials, their actions are often unimpeded.

To protect against such attacks, administrators should prioritize monitoring for suspicious activity, keep software up-to-date, and educate users about the dangers of phishing emails. By staying informed and proactive, organizations can reduce their risk of falling victim to these types of attacks.


Source: Bleeping Computer — 2026-09-01