Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Former President Joe Biden Will Attend Sept. 11 Ceremony in New York

    September 1, 2026

    OpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber Abilities

    September 1, 2026

    OpenAI supports California’s bill to advance youth AI safety

    September 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Former President Joe Biden Will Attend Sept. 11 Ceremony in New York
    • OpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber Abilities
    • OpenAI supports California’s bill to advance youth AI safety
    • Hackers abuse Faronics Deploy admin tool to install ScreenConnect
    • OpenClaw 2.0 Is Here: What Changed, Why It Took Two Months, and How It Stacks Up Against Hermes
    • One of Earth’s driest places was just covered in snow
    • People Fixing The World – Fighting the silent killer
    • Rooting tree seed production in local knowledge boosts forest restoration outcomes (commentary)
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers abuse Faronics Deploy admin tool to install ScreenConnect

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 1, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.

    In activity observed between July 21 and August 20, Faronics-themed lures reached more than 457 endpoints via emails disguised as invoices, tax documents, or other business files.

    Faronics Deploy is a cloud-based endpoint management platform that allows IT administrators to remotely enroll and manage computers, deploy software, and execute scripts.

    Researchers at managed detection and response company (MDR) Huntress say that the embedded malicious links lead to a website that profiles potential targets and guides them through a malicious download flow.

    If the website is reached from an analysis environment, a decoy routine is activated, such as displaying an error message.

    Huntress explains that a potential victim is prompted to download and launch a legitimate, signed Faronics Deploy installer that is disguised as an Adobe document, a reader app, or a plugin update.

    Fake Adobe download page
    Fake Adobe download page
    Source: Huntress

    When the victim runs the Faronics installer, often named ‘Adobe.exe,’ their computer is enrolled in a Faronics deployment controlled by the attackers.

    The threat actor then uses Faronics’ remote-deployment functionality to execute PowerShell scripts on the enrolled computer without further user interaction.

    These scripts download additional tools from the attacker’s infrastructure or external locations, including GitHub, eventually installing another legitimate remote access tool, ConnectWise ScreenConnect.

    “The delivery method varies between scripts, with observed examples using curl or mshta to retrieve additional content, while others invoke msiexec to install payloads hosted on attacker-controlled infrastructure,” Huntress says.

    “These scripts are subsequently used to install ScreenConnect, establishing an additional remote access mechanism on the compromised endpoint.”

    ScreenConnect gives attackers an additional remote-access channel independent of Faronics, providing hands-on remote control better suited to interactive access while also serving as redundancy if the malicious Faronics deployment is identified and terminated, or if defenders remove its agent.

    Huntress notified Faronics of its findings on August 5, and the vendor confirmed the observed malicious activity, countering it by implementing additional anti-abuse measures.

    Moreover, Faronics has contacted victimized organizations to notify them about potential compromise.

    According to Huntress, the malicious activity dropped significantly starting August 21, indicating that Faronics’ actions worked.

    Huntress recommends that administrators check the “C:ProgramDataFaronicsLogs” location for a ScriptRunner.log file, which may preserve remotely executed script names and download URLs.

    The company says that the ck parameter in Faronics configuration requests is also an indicator, as it identifies the associated customer deployment and can help identify compromised endpoints or malicious accounts.

    Administrators should also look for ScreenConnect installations where it is not normally deployed.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Abuse Admin Deploy Faronics hackers install ScreenConnect tool
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

    Palo Alto Networks Acquires AI Agent Platform Console

    Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense

    Critical Langflow flaw exploited to steal OpenAI and AWS keys

    13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

    Novocure data breach affects more than 1,400 cancer patients

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Former President Joe Biden Will Attend Sept. 11 Ceremony in New York

    September 1, 2026

    OpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber Abilities

    September 1, 2026

    OpenAI supports California’s bill to advance youth AI safety

    September 1, 2026

    Hackers abuse Faronics Deploy admin tool to install ScreenConnect

    September 1, 2026
    Latest Posts

    Bitcoin Only Makes Up 1% Of Legendary Investor Ray Dalio’s Portfolio

    July 30, 2026

    AI Harnesses Burst With Potential Exploit Opps

    July 30, 2026

    LinkedIn actually adds a ‘seems like AI slop’ button

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Former President Joe Biden Will Attend Sept. 11 Ceremony in New York

    September 1, 2026

    OpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber Abilities

    September 1, 2026

    OpenAI supports California’s bill to advance youth AI safety

    September 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.