Attackers are abusing the legitimate Faronics Deploy platform to enrol victim computers in malicious deployments and install ScreenConnect remote access software.

The phishing activity ran from July 21 to August 20 and reached more than 457 endpoints. Attackers used messages disguised as invoices, tax documents and other business files.

Phishing lures use a legitimate installer

Faronics Deploy is a cloud-based endpoint management platform that lets IT teams enrol devices, deploy software and run scripts remotely.

Researchers at Huntress found that phishing emails directed targets to malicious websites. These sites assessed visitors before starting a download flow. When the site detected a security analysis environment, it showed a decoy error message instead.

Other visitors saw prompts to download a legitimate, signed Faronics Deploy installer. Attackers disguised the installer as an Adobe document, reader application or plugin update.

The installer often used the filename Adobe.exe. Once a victim launched it, the attackers enrolled the computer into a Faronics deployment that they controlled.

Attackers deploy scripts and ScreenConnect

After enrolling a device, the attackers used Faronics Deploy to run PowerShell scripts without further interaction from the victim.

The scripts downloaded extra tools from attacker-controlled infrastructure and other online locations. Some used curl or mshta to retrieve content, while others used msiexec to install hosted payloads.

The Faronics Deploy abuse eventually installed ConnectWise ScreenConnect, a legitimate remote support tool.

ScreenConnect gives attackers an additional way to control a compromised device. It can also preserve their access if defenders identify and remove the malicious Faronics deployment.

Faronics took action against malicious use

Huntress notified Faronics about the campaign on August 5. The vendor confirmed the abuse and introduced additional measures to prevent it.

Faronics also contacted affected organisations about possible compromise. Huntress observed a sharp decline in malicious activity from August 21, suggesting that the vendor’s response disrupted the campaign.

Administrators should check C:\ProgramData\Faronics\Logs\ for a ScriptRunner.log file, which may include names of remotely run scripts and downloaded URLs.

They should also investigate unexpected ScreenConnect installations and review Faronics configuration requests for the ck parameter, which can help identify the associated deployment.


0 responses to “Hackers Abuse Faronics Deploy to Install ScreenConnect”