Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control of computers and install ConnectWise ScreenConnect, according to researchers at managed detection and response company Huntress.
Between July 21 and August 20, Faronics-themed emails disguised as invoices, tax documents, or other business files reached more than 457 endpoints. Malicious links led targets through a download flow that profiled visitors and showed decoy errors in analysis environments.
Victims were prompted to launch a legitimate, signed Faronics Deploy installer disguised as an Adobe document, reader app, or plugin update. Often named Adobe.exe, the installer enrolled the computer in a deployment controlled by the attackers.
The attackers then used Faronics’ remote-deployment functionality to run PowerShell scripts without further user interaction. The scripts downloaded additional tools from attacker infrastructure or external locations, including GitHub, and installed ScreenConnect. Huntress observed scripts using curl, mshta, or msiexec to retrieve or install content.
Huntress notified Faronics on August 5. Faronics confirmed the activity, added anti-abuse measures, and contacted affected organizations. The activity dropped significantly starting August 21, according to Huntress.
Comments
0No comments yet. Be the first to comment.