Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hackers abuse Faronics Deploy admin tool to install ScreenConnect

    September 1, 2026

    This ‘Digital Camouflage’ Shirt Confuses AI-Powered Surveillance Cameras

    September 1, 2026

    Dual-RMM Phishing and PowerShell RAT Campaign Hits SLTTs

    September 1, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Hackers abuse Faronics Deploy admin tool to install ScreenConnect
    News

    Hackers abuse Faronics Deploy admin tool to install ScreenConnect

    adminBy adminSeptember 1, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Hackers abuse Faronics Deploy admin tool to install ScreenConnect

    Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.

    In activity observed between July 21 and August 20, Faronics-themed lures reached more than 457 endpoints via emails disguised as invoices, tax documents, or other business files.

    Faronics Deploy is a cloud-based endpoint management platform that allows IT administrators to remotely enroll and manage computers, deploy software, and execute scripts.

    Researchers at managed detection and response company (MDR) Huntress say that the embedded malicious links lead to a website that profiles potential targets and guides them through a malicious download flow.

    If the website is reached from an analysis environment, a decoy routine is activated, such as displaying an error message.

    Huntress explains that a potential victim is prompted to download and launch a legitimate, signed Faronics Deploy installer that is disguised as an Adobe document, a reader app, or a plugin update.

    Fake Adobe download page
    Fake Adobe download page
    Source: Huntress

    When the victim runs the Faronics installer, often named ‘Adobe.exe,’ their computer is enrolled in a Faronics deployment controlled by the attackers.

    The threat actor then uses Faronics’ remote-deployment functionality to execute PowerShell scripts on the enrolled computer without further user interaction.

    These scripts download additional tools from the attacker’s infrastructure or external locations, including GitHub, eventually installing another legitimate remote access tool, ConnectWise ScreenConnect.

    “The delivery method varies between scripts, with observed examples using curl or mshta to retrieve additional content, while others invoke msiexec to install payloads hosted on attacker-controlled infrastructure,” Huntress says.

    “These scripts are subsequently used to install ScreenConnect, establishing an additional remote access mechanism on the compromised endpoint.”

    ScreenConnect gives attackers an additional remote-access channel independent of Faronics, providing hands-on remote control better suited to interactive access while also serving as redundancy if the malicious Faronics deployment is identified and terminated, or if defenders remove its agent.

    Huntress notified Faronics of its findings on August 5, and the vendor confirmed the observed malicious activity, countering it by implementing additional anti-abuse measures.

    Moreover, Faronics has contacted victimized organizations to notify them about potential compromise.

    According to Huntress, the malicious activity dropped significantly starting August 21, indicating that Faronics’ actions worked.

    Huntress recommends that administrators check the “C:\ProgramData\Faronics\Logs\” location for a ScriptRunner.log file, which may preserve remotely executed script names and download URLs.

    The company says that the ck parameter in Faronics configuration requests is also an indicator, as it identifies the associated customer deployment and can help identify compromised endpoints or malicious accounts.

    Administrators should also look for ScreenConnect installations where it is not normally deployed.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThis ‘Digital Camouflage’ Shirt Confuses AI-Powered Surveillance Cameras
    admin
    • Website

    Related Posts

    News

    This ‘Digital Camouflage’ Shirt Confuses AI-Powered Surveillance Cameras

    September 1, 2026
    News

    Dual-RMM Phishing and PowerShell RAT Campaign Hits SLTTs

    September 1, 2026
    News

    Oklahoma Tells City It Can’t Charge $17,125.44 for a Records Request Related to Data Center Arrest

    September 1, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    Hackers abuse Faronics Deploy admin tool to install ScreenConnect

    September 1, 2026

    This ‘Digital Camouflage’ Shirt Confuses AI-Powered Surveillance Cameras

    September 1, 2026

    Dual-RMM Phishing and PowerShell RAT Campaign Hits SLTTs

    September 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.