Phishing attacks misuse Faronics Deploy to deploy ScreenConnect remote access

Phishing campaigns are abusing the legitimate Faronics Deploy endpoint management platform to enroll victim computers and then install ConnectWise ScreenConnect for persistent remote access. The attacks, observed from July 21 to August 20, targeted over 457 endpoints with emails disguised as invoices or tax documents. Huntress researchers noted that the malicious flow uses decoy routines to evade analysis environments.
The campaign ran from July 21 to August 20, reaching over 457 endpoints through emails disguised as invoices or tax documents. Huntress researchers found that the attack chain begins with a profiling website that detects analysis environments and shows decoy errors instead of the malicious flow. Victims are tricked into running a legitimate signed Faronics Deploy installer, often named "Adobe.exe," which enrolls their machine into an attacker-controlled deployment.
Once enrolled, attackers use Faronics' remote deployment to execute PowerShell scripts via curl, mshta, or msiexec, pulling additional payloads from GitHub or attacker infrastructure. These scripts install ConnectWise ScreenConnect, giving attackers a second remote access channel independent of Faronics. Huntress notified Faronics on August 5, and the vendor implemented anti-abuse measures and contacted affected organizations, with malicious activity dropping significantly after August 21.
This campaign demonstrates how trusted administrative tools can be repurposed for intrusion, potentially affecting organizations that rely on endpoint management platforms. Businesses receiving phishing emails disguised as invoices or tax documents could face unauthorized remote access, data theft, or ransomware deployment. The dual remote-access channels make detection and removal more difficult, meaning smaller companies without dedicated security teams may be especially vulnerable. While Faronics' response appears effective, this incident could prompt broader scrutiny of how legitimate management tools are monitored for abuse across the industry.