Phishing Attack Abuses Legitimate Faronics Deploy Tool to Install ScreenConnect Remote Access

Campaign targeted over 457 endpoints between July and August before Faronics implemented anti-abuse measures

edit
By LineZotpaper
Published
Read Time2 min
Cybercriminals are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ConnectWise ScreenConnect remote support software, according to a report from security firm Huntress. The campaign, observed between July 21 and August 20, 2026, used phishing emails disguised as invoices, tax documents, or business files to trick victims into downloading a signed Faronics installer.

Researchers at managed detection and response company Huntress reported that phishing actors are exploiting Faronics Deploy, a cloud-based endpoint management platform used by IT administrators to remotely enroll computers, deploy software, and execute scripts. The campaign reached more than 457 endpoints.

The embedded malicious links in the phishing emails lead to a website that profiles potential targets. If the website detects an analysis environment, it triggers a decoy routine, such as displaying an error message. Otherwise, victims are prompted to download and launch a legitimate, signed Faronics Deploy installer disguised as an Adobe document, a reader app, or a plugin update.

When the victim runs the installer — often named 'Adobe.exe' — their computer is enrolled in a Faronics deployment controlled by the attackers. The threat actor then uses Faronics' remote-deployment functionality to execute PowerShell scripts on the enrolled computer without further user interaction. These scripts download additional tools from the attacker's infrastructure or external locations, including GitHub, eventually installing ScreenConnect.

Huntress explains that ScreenConnect provides an additional remote-access channel independent of Faronics, offering hands-on control better suited for interactive access. It also serves as redundancy if the malicious Faronics deployment is identified and terminated, or if defenders remove its agent.

Huntress notified Faronics of its findings on August 5. The vendor confirmed the malicious activity and implemented additional anti-abuse measures. Faronics also contacted victimized organizations to notify them about potential compromise. Malicious activity dropped significantly starting August 21, indicating that Faronics' actions were effective.

Huntress recommends that administrators check the 'C:\ProgramData\Faronics\Logs' location for a ScriptRunner.log file, which may preserve remotely executed script names and download URLs. The 'ck' parameter in Faronics configuration requests can also help identify compromised endpoints or malicious accounts.

§

Analysis

Why This Matters

  • This attack chain exploits a trusted, legitimate administrative tool (Faronics Deploy) to bypass security controls and deploy remote access software, making detection difficult for defenders.
  • The use of a signed installer from a reputable vendor allows the malware delivery to evade endpoint security solutions that might flag unknown or unsigned files.
  • The campaign's reach — over 457 endpoints — shows that phishing attacks leveraging legitimate platforms remain a significant threat to organizations.

Background

Faronics Deploy is a cloud-based endpoint management platform used by IT teams to remotely manage computers, deploy software, and run scripts. Legitimate administrative tools like these have been increasingly targeted by attackers, who abuse them for lateral movement and remote access. This 'living off the land' technique makes malicious activity harder to distinguish from legitimate administrative actions. ConnectWise ScreenConnect is a widely used remote support and access tool, often abused by threat actors for persistent access.

Key Perspectives

Huntress (Security Researchers): Emphasize that the attack leverages a trusted platform to install additional remote access tools, requiring administrators to monitor for unusual Faronics Deploy usage and check logs for suspicious script execution. Faronics: Confirmed the malicious activity and responded by implementing additional anti-abuse measures and contacting affected organizations. The vendor's quick action appears to have curbed the campaign. Victim Organizations: Face the challenge of detecting unauthorized use of legitimate management tools and may need to review their own Faronics deployments for signs of compromise.

What to Watch

  • Whether similar attacks using other endpoint management platforms emerge.
  • Further updates from Faronics on additional security enhancements or account reviews.
  • Huntress may release additional indicators of compromise or detection guidance.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.