<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Hackers abuse Faronics Deploy admin tool to install ScreenConnect]]></title><description><![CDATA[<p dir="auto">Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install ScreenConnect remote support software. The attack chain leverages the trusted nature of Faronics Deploy, which is designed for IT administrators to manage endpoints, making the malicious activity harder to detect by security tools and users alike.</p>
<p dir="auto">The campaign begins with a phishing email that tricks the recipient into running a malicious script or executable. Once executed, the malware connects to the Faronics Deploy service using stolen or misappropriated credentials, effectively turning the victim's machine into a managed endpoint under the attacker's control. From there, the attackers silently deploy ScreenConnect, a legitimate remote access tool, to establish persistent interactive access to the compromised system.</p>
<p dir="auto">Key technical details of the attack include:</p>
<ul>
<li>The abuse of Faronics Deploy's legitimate administrative functions to bypass application allowlisting and endpoint detection and response (EDR) products.</li>
<li>ScreenConnect is installed without user interaction, using the platform's deployment mechanisms rather than typical droppers or loaders.</li>
<li>The attackers use the remote access session to perform follow-up actions such as credential harvesting, data exfiltration, or deploying additional payloads.</li>
<li>Faronics Deploy is not compromised; rather, the attackers are abusing valid accounts, likely obtained through phishing or infostealer malware.</li>
</ul>
<p dir="auto">Indicators that an environment may have been targeted include:</p>
<ul>
<li>Unexpected Faronics Deploy agent enrollment for machines that are not part of an organization's legitimate deployment setup.</li>
<li>Unusual ScreenConnect client installations appearing on endpoints without corresponding IT helpdesk activity.</li>
<li>Outbound network connections to Faronics and ScreenConnect infrastructure originating from non-admin workstations.</li>
</ul>
<p dir="auto">To mitigate this threat, administrators should:</p>
<ul>
<li>Audit all Faronics Deploy accounts for unrecognized users or roles and enforce multi-factor authentication.</li>
<li>Restrict ScreenConnect installation and execution to authorized administrative accounts only, using application controls where possible.</li>
<li>Monitor for new endpoint management enrollments and remote support sessions in logs, correlating them with helpdesk tickets.</li>
<li>Review email gateway rules for phishing lures that reference IT support or remote access tools.</li>
</ul>
<p dir="auto">This campaign highlights a growing trend: attackers increasingly abuse legitimate remote management and support tools to blend in with normal administrative activity, making detection reliant on behavioral analysis rather than signature-based defenses.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Is your organization auditing for unauthorized enrollments in remote management platforms like Faronics Deploy, or are you relying on EDR rules to catch this behavior post-installation?</p>
]]></description><link>https://xploitlk.com/topic/183/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:37:25 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/183.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 01 Sep 2026 22:30:25 GMT</pubDate><ttl>60</ttl></channel></rss>