Phishing actors are abusing the legitimate Faronics Deploy platform to enroll victim devices and use remote deployment features to run PowerShell scripts that install ConnectWise ScreenConnect. Huntress observed the campaign delivering Faronics-themed lures to more than 457 endpoints and noted that Faronics has since added anti-abuse measures and contacted affected organizations. #FaronicsDeploy #ConnectWiseScreenConnect #Huntress
Keypoints
- Attackers used Faronics-themed phishing emails to target more than 457 endpoints.
- Victims were tricked into downloading a legitimate, signed Faronics Deploy installer disguised as an Adobe-related file.
- Once enrolled, compromised computers were controlled through Faronics remote-deployment features.
- Attackers executed PowerShell scripts to fetch additional tools and install ConnectWise ScreenConnect.
- Faronics confirmed the abuse, added anti-abuse controls, and notified impacted organizations.