Threat Actors Exploit Faronics Deploy for Remote Access via Phishing
Article Content
Threat actors are exploiting Faronics Deploy, a legitimate endpoint management tool, to execute malicious PowerShell scripts and install ScreenConnect on compromised systems. Between July 21 and August 20, over 457 endpoints were targeted through phishing emails disguised as business documents. Victims are tricked into downloading a Faronics installer that masquerades as legitimate software, allowing attackers to gain remote control. Huntress reported the malicious activity to Faronics on August 5, prompting the vendor to implement countermeasures. Following these actions, the observed malicious activity significantly decreased starting August 21. Key forensic artifacts, such as ScriptRunner.log, can assist in incident investigations. The attack method involves phishing lures, remote script execution, and the installation of additional remote access tools. Faronics has contacted affected organizations to notify them of potential compromises.
Key Points: • Attackers exploit Faronics Deploy to gain remote control through phishing. • Over 457 endpoints were targeted in a month-long campaign. • Faronics implemented countermeasures that reduced malicious activity significantly.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.