Hackers abuse Faronics Deploy admin tool to install ScreenConnect
AI Summary
Hackers are exploiting the legitimate Faronics Deploy endpoint management tool to gain remote administrative access to victim systems by tricking users into installing a maliciously repurposed, signed installer disguised as an Adobe-related executable. The installer enrolls the victim's machine into an attacker-controlled Faronics deployment, enabling the execution of PowerShell scripts that deploy additional payloads, including ConnectWise ScreenConnect, a remote access tool used for persistent and interactive control. The attack uses phishing emails with business-themed lures, such as fake invoices, and includes anti-analysis techniques to evade detection in sandboxed environments. Activity declined after Faronics implemented anti-abuse measures in response to disclosure by Huntress.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | Adobe.exe | Details → |