Phishing Campaign Abuses Faronics Deploy to Install ScreenConnect
What Happened
According to BleepingComputer, phishing actors are abusing Faronics Deploy — a legitimate endpoint-management platform used by IT administrators — to gain remote administrative control over victim computers. Once access is established, the attackers use it to install ScreenConnect, a legitimate remote-support tool that is frequently repurposed by threat actors for persistent remote access.
Why It Matters
This is another example of the "living-off-trusted-software" pattern: rather than deploying custom malware, attackers ride on signed, legitimate administrative tools that are unlikely to be flagged by antivirus or blocked by application allowlisting. Because Faronics Deploy is a real IT-management product, its presence and network traffic can blend into normal enterprise activity, and ScreenConnect is widely used for legitimate helpdesk support — making both tools difficult to distinguish from routine admin work without behavioral context. Organizations that use, or whose employees encounter, either product are potentially exposed, particularly through initial-access phishing.
What Defenders Should Watch For
- Unexpected installation or first-time execution of Faronics Deploy or ScreenConnect binaries on endpoints where they are not part of the standard software baseline.
- New ScreenConnect relay/instance connections originating from unfamiliar or non-corporate infrastructure.
- Phishing emails referencing IT tooling, software updates, or remote support that lead to installer downloads.
- Process lineage where a remote-access or remote-support tool is spawned shortly after a management-agent installation on a host with no prior record of that agent.
- Review of allowlisting and application-control policies to ensure legitimate remote-management tools are only permitted to run from sanctioned sources and are monitored for anomalous installs.
General mitigations apply: restrict or monitor installation of remote-management/remote-support software via EDR and application control, and reinforce phishing awareness given this appears to be phishing-driven.
Developing Intel
This is a net-new report and details on scope, targeting, and threat-actor attribution are still emerging. For the original reporting, see BleepingComputer's coverage.