Phishing attack exploits Faronics Deploy for remote control

A large-scale phishing campaign is exploiting the Faronics Deploy platform to gain administrative access to corporate computers and install the remote support software ScreenConnect. Between July 21 and August 20, over 457 endpoints were reached by deceptive emails simulating invoices, tax documents, or other corporate files.

Quick Response

  • Attacks exploit Faronics Deploy to gain administrative access
  • ScreenConnect is installed as a backdoor for remote control
  • Faronics has implemented anti-abuse measures reducing attacks
  • Administrators must check ScriptRunner.log and ck parameters

Infection Mechanism

The attackers send emails with malicious links leading to a profiling website. If the site is reached from an analysis environment, an error message is displayed. For legitimate users, the site guides the installation of a legitimate but tampered Faronics Deploy installer, often disguised as an Adobe file.

Privilege Escalation

Once the installer is executed, the computer is enrolled in a Faronics deployment controlled by the attackers. Through remote deployment features, the attackers run PowerShell scripts that download additional tools, including payloads hosted on GitHub. ScreenConnect is then installed as a secondary remote access mechanism.

Dual Access Channel

ScreenConnect provides attackers with an alternative remote access channel, independent of Faronics. This tool offers more effective interactive control and serves as redundancy in case the malicious Faronics deployment is detected and removed.

Faronics Response

Huntress notified Faronics of its findings on August 5. The company confirmed the malicious activities and implemented additional anti-abuse measures. Faronics also contacted the victimized organizations to notify them of the potential compromise. As of August 21, malicious activities have significantly decreased.

Compromise Indicators

Administrators should check the location "C:\ProgramData\Faronics\Logs\" for a ScriptRunner.log file, which may retain the names of remotely executed scripts and download URLs. The ck parameter in Faronics configuration requests is another indicator, identifying the associated client deployment and helping to identify compromised endpoints or malicious accounts. Additionally, installations of ScreenConnect where they are not normally distributed should be sought.

Limitations of Protections

Huntress emphasizes that overall prevention scores can hide activities following the initial access. Once attackers use valid credentials, prevention sharply decreases. The Blue Report 2026 measures technical defenses technique by technique through 338 million simulations executed in customer production environments.

Preventive Measures

To mitigate these attacks, administrators should implement strict controls on endpoint management software, actively monitor installations of remote access tools, and adopt managed detection and response solutions to detect suspicious activities.

Security Implications

This campaign highlights the risk posed by legitimate endpoint management tools when abused. Organizations should carefully evaluate the use of such platforms and implement additional security controls to prevent abuse. End-user training on identifying phishing emails is equally crucial to reduce the risk of initial infection.

In-Depth Technical Analysis

The scripts used to download additional payloads vary in delivery methods. Some observed examples use curl or mshta to retrieve additional content, while others invoke msiexec to install payloads hosted on attacker-controlled infrastructures. This flexible approach demonstrates the attackers' ability to adapt to target defenses.

Impact on Endpoint Management

This attack raises questions about the responsibility of endpoint management software providers. The security community may need to develop stricter standards for designing such platforms, including built-in anomaly detection features and tighter access limits.

Industry Trends

The Blue Report 2026 highlights a concerning trend: technical defenses vary significantly among different organizations. This underscores the need for continuous benchmarking and knowledge sharing within the industry to collectively improve defensive capabilities.

Post-Incident Security Approach

After removing ScreenConnect and the compromised components of Faronics Deploy, it is essential to conduct a thorough forensic investigation to determine the extent of the compromise. This includes analyzing system logs, searching for other backdoors, and assessing potential data exfiltration.

Collaboration Between Companies and Providers

Faronics' proactive approach in notifying victimized organizations represents a best practice for the industry. Greater collaboration between software providers and user companies can improve incident response and reduce the overall impact of these campaigns.

Considerations for User Training

Phishing attack simulations should include scenarios that replicate the tactics observed in this campaign. Users should be trained to recognize suspicious emails that simulate legitimate corporate documents and to verify the authenticity of links before clicking.

Research Perspectives

The security community should further explore the abuse of legitimate endpoint management tools. Research on how to improve visibility of suspicious activities within these environments could lead to innovative solutions to prevent future abuses.

Geographical Considerations

Analysis of compromised endpoints may reveal interesting geographical patterns, indicating potential preferred targets or regional defense differences. This information could be useful for more efficiently allocating security resources.

Impact on Trust in Legitimate Software

These attacks could erode trust in legitimate endpoint management platforms. Organizations may consider implementing alternative solutions or adopting a more cautious approach to remote endpoint management.

Regulatory Developments

Potential regulatory developments may emerge from this campaign, especially if victimized organizations suffer significant financial losses. This could lead to new laws on the liability of software providers and endpoint security management.

Advanced Detection Tools

The development of detection tools specific to suspicious activities within Faronics-managed environments could be a priority for security teams. These tools could analyze Faronics Deploy usage patterns to identify anomalous behaviors.

Lessons Learned for Administrators

Administrators should review their endpoint management strategies in light of this campaign. This includes evaluating alternative solutions for remote management and implementing stricter access controls to prevent abuse of these platforms.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.

📰 Source: bleepingcomputer.com ↗
✍️ Elaboration: Sebastiano · GoYou.it