Researchers at managed detection and response company Huntress reported that phishing actors are exploiting Faronics Deploy, a cloud-based endpoint management platform used by IT administrators to remotely enroll computers, deploy software, and execute scripts. The campaign reached more than 457 endpoints.
The embedded malicious links in the phishing emails lead to a website that profiles potential targets. If the website detects an analysis environment, it triggers a decoy routine, such as displaying an error message. Otherwise, victims are prompted to download and launch a legitimate, signed Faronics Deploy installer disguised as an Adobe document, a reader app, or a plugin update.
When the victim runs the installer — often named 'Adobe.exe' — their computer is enrolled in a Faronics deployment controlled by the attackers. The threat actor then uses Faronics' remote-deployment functionality to execute PowerShell scripts on the enrolled computer without further user interaction. These scripts download additional tools from the attacker's infrastructure or external locations, including GitHub, eventually installing ScreenConnect.
Huntress explains that ScreenConnect provides an additional remote-access channel independent of Faronics, offering hands-on control better suited for interactive access. It also serves as redundancy if the malicious Faronics deployment is identified and terminated, or if defenders remove its agent.
Huntress notified Faronics of its findings on August 5. The vendor confirmed the malicious activity and implemented additional anti-abuse measures. Faronics also contacted victimized organizations to notify them about potential compromise. Malicious activity dropped significantly starting August 21, indicating that Faronics' actions were effective.
Huntress recommends that administrators check the 'C:\ProgramData\Faronics\Logs' location for a ScriptRunner.log file, which may preserve remotely executed script names and download URLs. The 'ck' parameter in Faronics configuration requests can also help identify compromised endpoints or malicious accounts.