MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-01 · via BleepingComputer

Phishing attacks misuse Faronics Deploy to deploy ScreenConnect remote access

Image via BleepingComputer
Image via BleepingComputer

Phishing campaigns are abusing the legitimate Faronics Deploy endpoint management platform to enroll victim computers and then install ConnectWise ScreenConnect for persistent remote access. The attacks, observed from July 21 to August 20, targeted over 457 endpoints with emails disguised as invoices or tax documents. Huntress researchers noted that the malicious flow uses decoy routines to evade analysis environments.

Expanded Detail

The campaign ran from July 21 to August 20, reaching over 457 endpoints through emails disguised as invoices or tax documents. Huntress researchers found that the attack chain begins with a profiling website that detects analysis environments and shows decoy errors instead of the malicious flow. Victims are tricked into running a legitimate signed Faronics Deploy installer, often named "Adobe.exe," which enrolls their machine into an attacker-controlled deployment.

Once enrolled, attackers use Faronics' remote deployment to execute PowerShell scripts via curl, mshta, or msiexec, pulling additional payloads from GitHub or attacker infrastructure. These scripts install ConnectWise ScreenConnect, giving attackers a second remote access channel independent of Faronics. Huntress notified Faronics on August 5, and the vendor implemented anti-abuse measures and contacted affected organizations, with malicious activity dropping significantly after August 21.

Context

This campaign demonstrates how trusted administrative tools can be repurposed for intrusion, potentially affecting organizations that rely on endpoint management platforms. Businesses receiving phishing emails disguised as invoices or tax documents could face unauthorized remote access, data theft, or ransomware deployment. The dual remote-access channels make detection and removal more difficult, meaning smaller companies without dedicated security teams may be especially vulnerable. While Faronics' response appears effective, this incident could prompt broader scrutiny of how legitimate management tools are monitored for abuse across the industry.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Hackers abuse Faronics Deploy admin tool to install ScreenConnect.” Browse more stories.