Hackers have abused the legitimate Faronics Deploy management platform to gain administrative control of computers and install ConnectWise ScreenConnect, according to cybersecurity firm Huntress.
The campaign reached more than 457 endpoints between 21 July and 20 August through phishing emails made to resemble invoices, tax documents and other business files. The messages directed recipients to websites designed to identify potential victims and lead them through a malicious download process.
Faronics Deploy is a cloud-based tool used by IT teams to enrol and manage computers, deploy software and run scripts remotely. In this case, attackers exploited those capabilities after persuading victims to install the platform.
Huntress said the websites displayed decoy error messages when accessed from environments associated with security analysis. Genuine targets were instead prompted to download and open what appeared to be an Adobe document, reader application or plug-in update.
The file was a legitimate, digitally signed Faronics Deploy installer, often given the name “Adobe.exe”. Once launched, it enrolled the computer in a Faronics deployment controlled by the attackers.
The criminals could then use Faronics Deploy to run PowerShell scripts on the compromised machine without requiring further action from the victim. The scripts retrieved additional software from attacker-controlled infrastructure or external services including GitHub.
Some of the scripts used tools such as curl or mshta to download further content, while others called msiexec to install software hosted remotely, Huntress said.
ScreenConnect provided a second route into compromised computers
The operation ultimately installed ScreenConnect, a legitimate remote-support product. That gave the attackers a separate channel for interactive access to affected computers, independent of the Faronics agent.
Huntress said the additional software could allow continued access if the malicious Faronics deployment was discovered and shut down, or if its agent was removed by defenders.
The security company alerted Faronics to the activity on 5 August. Faronics confirmed the abuse and introduced additional measures intended to prevent its platform being misused, while also contacting organisations that may have been affected.
Huntress said the volume of malicious activity fell sharply from 21 August, suggesting the measures had disrupted the campaign.
Administrators investigating a possible compromise have been advised to inspect C:\ProgramData\Faronics\Logs\ for a file called ScriptRunner.log. The log may contain the names of remotely executed scripts and the web addresses from which files were downloaded.
They should also review the ck parameter in Faronics configuration requests, which identifies the customer deployment and may help uncover compromised endpoints or unauthorised accounts.
Unexpected installations of ScreenConnect should be treated as another warning sign, particularly on computers where the remote-access software is not normally used.
