Executive Summary
Between July and August 2026, cybercriminals exploited the legitimate Faronics Deploy endpoint management platform to gain unauthorized administrative control over victim computers. The attackers used phishing emails disguised as invoices and tax documents to trick users into downloading a legitimate but malicious Faronics Deploy installer. Once installed, the threat actors remotely executed PowerShell scripts to deploy ConnectWise ScreenConnect remote access software, establishing persistent backdoor access to over 457 endpoints across multiple organizations.
This incident highlights the growing trend of Living-off-the-Land (LotL) attacks where cybercriminals abuse legitimate administrative tools to bypass traditional security controls and establish covert command-and-control channels.
Why This Matters Now
The abuse of legitimate IT management tools like Faronics Deploy represents a sophisticated evolution in attack techniques that traditional security solutions struggle to detect, making this incident particularly relevant as organizations face increasing challenges in distinguishing between legitimate administrative activities and malicious exploitation.
Attack Path Analysis
Attackers used phishing emails with Faronics Deploy-themed lures to trick victims into downloading legitimate but malicious Faronics Deploy installers disguised as Adobe documents. Once installed, attackers gained remote administrative control through the compromised Faronics deployment, executed PowerShell scripts to download additional tools, and established persistent access via ScreenConnect remote access software for ongoing command and control operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Phishing emails disguised as invoices and tax documents delivered malicious links that profiled targets and guided them to download legitimate Faronics Deploy installers disguised as Adobe documents
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
User Execution: Malicious File
Masquerading: Match Legitimate Name or Location
Subvert Trust Controls: Code Signing
Command and Scripting Interpreter: PowerShell
Remote Access Software
Ingress Tool Transfer
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques for Secure Development
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Monitoring and Training
Control ID: 500.01(g)
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Identity Pillar
Control ID: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Controls Against Malware
Control ID: A.12.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical exposure as Faronics Deploy abuse enables RAT deployment via PowerShell, compromising endpoint management infrastructure and establishing persistent ScreenConnect backdoors.
Financial Services
High-value targets vulnerable to phishing campaigns deploying remote access tools, with regulatory compliance risks under PCI requirements for network segmentation.
Health Care / Life Sciences
Protected health information at risk from remote access tool campaigns bypassing encrypted traffic controls, violating HIPAA data protection requirements.
Education Management
Educational institutions face endpoint compromise through legitimate administrative tools abuse, enabling lateral movement across campus networks and student data exposure.
Sources
- Hackers abuse Faronics Deploy admin tool to install ScreenConnecthttps://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/Verified
- Faronics Deploy Abuse Campaign Analysishttps://www.huntress.com/blog/faronics-deploy-abuseVerified
- Faronics Deploy Official Product Pagehttps://www.faronics.com/products/faronics-deployVerified
- ConnectWise ScreenConnect Security Resourceshttps://www.connectwise.com/platform/unified-management/control/screenconnectVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have limited the blast radius of this Faronics Deploy compromise by constraining lateral movement through microsegmentation and controlling outbound communications to attacker infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely have reduced the scope of endpoint enrollment by limiting which systems could communicate with external deployment infrastructure during the initial compromise phase
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely have limited the scope of administrative access granted through the Faronics deployment by restricting which network resources newly enrolled endpoints could reach
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely have constrained PowerShell script execution across multiple endpoints by blocking unauthorized inter-workload communications within the compromised network segments
Control: Multicloud Visibility & Control
Mitigation: Network visibility controls would likely have detected and constrained the establishment of unauthorized remote access channels by monitoring suspicious outbound connections to ScreenConnect infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely have constrained data exfiltration capabilities by limiting outbound data flows from compromised endpoints to unauthorized external destinations through the ScreenConnect channels
The overall blast radius of potential ransomware deployment would likely have been significantly constrained due to limited lateral movement paths and reduced network reachability between compromised endpoints
Impact at a Glance
Affected Business Functions
- IT System Administration
- Remote Access Management
- Endpoint Security Management
- Network Operations
Estimated downtime: 3 days
Estimated loss: $25,000
Potential exposure of corporate network access credentials, system configurations, and administrative privileges. Risk of lateral movement within compromised networks and access to sensitive business data through established remote access channels.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent legitimate administrative tools from being enrolled in unauthorized external management platforms
- • Deploy Egress Security & Policy Enforcement to block PowerShell scripts from downloading payloads from external repositories like GitHub
- • Enable Multicloud Visibility & Control to detect anomalous remote access tool installations and unauthorized administrative enrollment activities
- • Activate Threat Detection & Anomaly Response capabilities to identify suspicious ScreenConnect and remote access tool deployments in environments where they are not normally used
- • Establish Cloud Native Security Fabric controls to prevent abuse of legitimate administrative tools through real-time policy enforcement and behavioral analysis



