V-Help
← All news
Security

Cybercriminals Exploit Faronics Deploy to Secretly Install ScreenConnect

Cybercriminals Exploit Faronics Deploy to Secretly Install ScreenConnect

Photo: BleepingComputer

Quick answer

Threat actors exploited the legitimate Faronics Deploy management tool to remotely execute PowerShell scripts and install ScreenConnect on compromised systems. The attacks were detected and partially neutralized.

In July and August of this year, cybersecurity experts detected a new wave of attacks where threat actors abused the legitimate Faronics Deploy tool to remotely control corporate systems and deploy additional software. According to a report by Huntress, the attacks were carried out via phishing campaigns containing fake invoices, tax documents, and other business files.

Between July 21 and August 20, over 457 endpoints were compromised. Malicious links redirected potential victims to fake pages that analyzed their systems and offered infected Faronics Deploy installers. If an attack was detected in a sandboxed environment, the system displayed fake errors to conceal real activities.

After installing the legitimate-looking Faronics Deploy installer—often disguised as an Adobe update or other software component—victims' computers automatically connected to a threat actor-controlled cloud environment. This allowed criminals to remotely execute PowerShell scripts without user interaction, downloading additional tools from external sources, including GitHub.

As a result, ScreenConnect—a legitimate remote access tool—was installed on compromised systems. It provided attackers with more convenient interactive control over the systems and served as a backup access channel in case the primary Faronics Deploy environment was detected or blocked.

Following the investigation, Huntress notified Faronics about the incident on August 5. The vendor quickly implemented additional security measures and contacted affected organizations to inform them of potential compromise. Starting August 21, attack volumes sharply declined, confirming the effectiveness of the countermeasures.

Common questions

How did attackers infiltrate systems through Faronics Deploy?
Attacks began with phishing emails containing links to fake download pages. Victims installed the legitimate Faronics Deploy installer, which was actually malicious, allowing criminals to remotely execute scripts and install ScreenConnect.
What security measures do experts recommend post-incident?
Researchers advise checking Faronics Deploy logs for suspicious scripts and URLs, as well as searching for unauthorized ScreenConnect installations. The vendor has strengthened anti-abuse measures and notified affected organizations.
Why is ScreenConnect used in such attacks?
ScreenConnect provides attackers with an additional interactive remote access channel, bypassing legitimate tool limitations and ensuring backup access if the primary attack is detected.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer