Executive Summary

Between July and August 2026, cybercriminals exploited the legitimate Faronics Deploy endpoint management platform to gain unauthorized administrative control over victim computers. The attackers used phishing emails disguised as invoices and tax documents to trick users into downloading a legitimate but malicious Faronics Deploy installer. Once installed, the threat actors remotely executed PowerShell scripts to deploy ConnectWise ScreenConnect remote access software, establishing persistent backdoor access to over 457 endpoints across multiple organizations.

This incident highlights the growing trend of Living-off-the-Land (LotL) attacks where cybercriminals abuse legitimate administrative tools to bypass traditional security controls and establish covert command-and-control channels.

Why This Matters Now

The abuse of legitimate IT management tools like Faronics Deploy represents a sophisticated evolution in attack techniques that traditional security solutions struggle to detect, making this incident particularly relevant as organizations face increasing challenges in distinguishing between legitimate administrative activities and malicious exploitation.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers tricked users into installing legitimate Faronics Deploy software through phishing emails, then enrolled victim machines into attacker-controlled deployment environments to remotely execute malicious scripts.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have limited the blast radius of this Faronics Deploy compromise by constraining lateral movement through microsegmentation and controlling outbound communications to attacker infrastructure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network segmentation policies would likely have reduced the scope of endpoint enrollment by limiting which systems could communicate with external deployment infrastructure during the initial compromise phase

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely have limited the scope of administrative access granted through the Faronics deployment by restricting which network resources newly enrolled endpoints could reach

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely have constrained PowerShell script execution across multiple endpoints by blocking unauthorized inter-workload communications within the compromised network segments

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Network visibility controls would likely have detected and constrained the establishment of unauthorized remote access channels by monitoring suspicious outbound connections to ScreenConnect infrastructure

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely have constrained data exfiltration capabilities by limiting outbound data flows from compromised endpoints to unauthorized external destinations through the ScreenConnect channels

Impact (Mitigations)

The overall blast radius of potential ransomware deployment would likely have been significantly constrained due to limited lateral movement paths and reduced network reachability between compromised endpoints

Impact at a Glance

Affected Business Functions

  • IT System Administration
  • Remote Access Management
  • Endpoint Security Management
  • Network Operations
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $25,000

Data Exposure

Potential exposure of corporate network access credentials, system configurations, and administrative privileges. Risk of lateral movement within compromised networks and access to sensitive business data through established remote access channels.

Recommended Actions

  • Implement Zero Trust Segmentation to prevent legitimate administrative tools from being enrolled in unauthorized external management platforms
  • Deploy Egress Security & Policy Enforcement to block PowerShell scripts from downloading payloads from external repositories like GitHub
  • Enable Multicloud Visibility & Control to detect anomalous remote access tool installations and unauthorized administrative enrollment activities
  • Activate Threat Detection & Anomaly Response capabilities to identify suspicious ScreenConnect and remote access tool deployments in environments where they are not normally used
  • Establish Cloud Native Security Fabric controls to prevent abuse of legitimate administrative tools through real-time policy enforcement and behavioral analysis

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image