highPhishing

Faronics Deploy Abuse for ScreenConnect Delivery

First seen Sep 2, 2026 · Updated Sep 2, 2026

phishingremote-access-toolliving-off-the-landinitial-accessscreenconnectendpoint-management-abuseagent-relevant

Threat actors are abusing the legitimate Faronics Deploy endpoint-management platform, likely delivered via phishing, to gain remote administrative control over victim machines. Once access is obtained, attackers use the platform's legitimate deployment capabilities to install ScreenConnect, a remote support tool commonly repurposed by attackers for persistence and lateral movement.

Technical Analysis

This campaign leverages a trusted, signed IT administration tool (Faronics Deploy) as a living-off-the-land vector to bypass security controls that would typically flag unsigned or unknown remote access software. Initial access appears to be phishing-based, tricking victims or IT staff into granting deployment access or credentials, after which the attackers push ScreenConnect as a secondary payload for persistent remote control. Because ScreenConnect provides full remote desktop and file transfer capability, it enables credential theft, lateral movement, and follow-on payload delivery including ransomware. Organizations running AI agent orchestration hosts or RAG pipelines on endpoints managed by Faronics Deploy are at risk of credential and API key theft if attackers gain administrative remote access, potentially exposing agent tool-use secrets and enabling manipulation of agent workflows or model endpoints.

Affected Systems

Windows endpoints managed via Faronics Deploy console; environments where Faronics Deploy agent software is installed for IT administration; systems subsequently targeted for ScreenConnect (ConnectWise Control) installation

Indicators of Compromise

  • ScreenConnect installer payloads delivered via Faronics Deploy console
  • Faronics Deploy admin console unauthorized access attempts
  • Phishing emails referencing IT deployment/software updates
  • (Specific hashes, C2 domains, and IPs not disclosed in source reporting)

Remediation Steps

  1. 1

    Audit Faronics Deploy Access

    Review administrative accounts and access logs for the Faronics Deploy console to identify unauthorized logins or configuration changes.

  2. 2

    Restrict and Monitor Remote Access Tools

    Implement application allowlisting to block unauthorized installation of ScreenConnect or other RMM tools not explicitly approved by IT.

  3. 3

    Enforce MFA on Admin Consoles

    Require multi-factor authentication for all endpoint management platform logins, including Faronics Deploy.

  4. 4

    User Awareness Training

    Educate staff, especially IT administrators, on phishing tactics targeting deployment and management tool credentials.

  5. 5

    Rotate Exposed Credentials

    If compromise is suspected, rotate all credentials and API keys accessible from affected endpoints, including those used by AI agent or automation tooling.

  6. 6

    Network Segmentation

    Limit lateral movement potential by segmenting endpoint management infrastructure from critical servers running AI agent or data pipeline workloads.

Industries Most Exposed

IT servicesmanaged service providerseducationhealthcareenterprise organizations using endpoint management platforms

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.