Threat Actors Exploit Faronics Deploy for Remote Access via Phishing

Threat Actors Exploit Faronics Deploy for Remote Access via Phishing

First seen 1 Sep 2026, 22:29 UTC Bleepingcomputerwww.huntress.com 69.0

Article Content

Browse articles
ThreatCluster

Threat actors are exploiting Faronics Deploy, a legitimate endpoint management tool, to execute malicious PowerShell scripts and install ScreenConnect on compromised systems. Between July 21 and August 20, over 457 endpoints were targeted through phishing emails disguised as business documents. Victims are tricked into downloading a Faronics installer that masquerades as legitimate software, allowing attackers to gain remote control. Huntress reported the malicious activity to Faronics on August 5, prompting the vendor to implement countermeasures. Following these actions, the observed malicious activity significantly decreased starting August 21. Key forensic artifacts, such as ScriptRunner.log, can assist in incident investigations. The attack method involves phishing lures, remote script execution, and the installation of additional remote access tools. Faronics has contacted affected organizations to notify them of potential compromises.

Key Points: • Attackers exploit Faronics Deploy to gain remote control through phishing. • Over 457 endpoints were targeted in a month-long campaign. • Faronics implemented countermeasures that reduced malicious activity significantly.

Timeline

2026-07-21
Phishing campaign begins
Threat actors start sending Faronics-themed phishing emails to potential victims, targeting over 457 endpoints.
Huntress
2026-08-05
Huntress notifies Faronics
Huntress reports the malicious activity to Faronics, prompting an investigation and response.
Huntress
2026-08-21
Malicious activity drops
Following Faronics' implementation of new measures, the observed malicious activity decreases significantly.
Huntress