Hackers abuse Faronics Deploy admin tool to install ScreenConnect

by · BleepingComputer

Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.

In activity observed between July 21 and August 20, Faronics-themed lures reached more than 457 endpoints via emails disguised as invoices, tax documents, or other business files.

Faronics Deploy is a cloud-based endpoint management platform that allows IT administrators to remotely enroll and manage computers, deploy software, and execute scripts.

Researchers at managed detection and response company (MDR) Huntress say that the embedded malicious links lead to a website that profiles potential targets and guides them through a malicious download flow.

If the website is reached from an analysis environment, a decoy routine is activated, such as displaying an error message.

Huntress explains that a potential victim is prompted to download and launch a legitimate, signed Faronics Deploy installer that is disguised as an Adobe document, a reader app, or a plugin update.

Fake Adobe download page
Source: Huntress

When the victim runs the Faronics installer, often named ‘Adobe.exe,’ their computer is enrolled in a Faronics deployment controlled by the attackers.

The threat actor then uses Faronics’ remote-deployment functionality to execute PowerShell scripts on the enrolled computer without further user interaction.

These scripts download additional tools from the attacker’s infrastructure or external locations, including GitHub, eventually installing another legitimate remote access tool, ConnectWise ScreenConnect.

“The delivery method varies between scripts, with observed examples using curl or mshta to retrieve additional content, while others invoke msiexec to install payloads hosted on attacker-controlled infrastructure,” Huntress says.

“These scripts are subsequently used to install ScreenConnect, establishing an additional remote access mechanism on the compromised endpoint.”

ScreenConnect gives attackers an additional remote-access channel independent of Faronics, providing hands-on remote control better suited to interactive access while also serving as redundancy if the malicious Faronics deployment is identified and terminated, or if defenders remove its agent.

Huntress notified Faronics of its findings on August 5, and the vendor confirmed the observed malicious activity, countering it by implementing additional anti-abuse measures.

Moreover, Faronics has contacted victimized organizations to notify them about potential compromise.

According to Huntress, the malicious activity dropped significantly starting August 21, indicating that Faronics’ actions worked.

Huntress recommends that administrators check the "C:\ProgramData\Faronics\Logs\" location for a ScriptRunner.log file, which may preserve remotely executed script names and download URLs.

The company says that the ck parameter in Faronics configuration requests is also an indicator, as it identifies the associated customer deployment and can help identify compromised endpoints or malicious accounts.

Administrators should also look for ScreenConnect installations where it is not normally deployed.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report