Phishing actors weaponized Faronics Deploy to slip in ScreenConnect
Phishing emails that looked like invoices or tax forms carried a signed Faronics Deploy installer named Adobe.exe. When victims ran it, the machine enrolled in a rogue Faronics deployment controlled by the attackers.
How the chain unfolded
The attackers used Faronics’s remote‑deployment feature to launch PowerShell scripts. Those scripts fetched additional tools and installed ConnectWise ScreenConnect, giving the criminals a persistent remote‑access channel.
Scope and timeline
Huntress observed activity from 21 July to 20 August, hitting more than 457 endpoints across multiple organisations.
Response from the vendor
Faronics was alerted on 5 August. The company confirmed the abuse and rolled out anti‑abuse controls. It also reached out to customers that might be compromised.
What you should check
Look for evidence of the deployment in the local log file:
C:\ProgramData\Faronics\Logs\ScriptRunner.log
Typical indicators include unknown PowerShell command lines, URLs pointing to external download locations, and the presence of ScreenConnect binaries in unexpected folders.
Practical steps
- Audit every system that has Faronics Deploy installed; confirm it is managed by an authorised IT team.
- Block execution of unsigned executables in the
C:\ProgramData\Faronicspath unless they are part of a known deployment. - Restrict remote‑deployment privileges to a limited set of service accounts.
- Enable logging for PowerShell script execution (‑ExecutionPolicy Bypass, ‑EncodedCommand) and forward those logs to a SIEM.
- If ScreenConnect is not part of your approved toolset, quarantine or uninstall any copies found.
