Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.
In activity observed between July 21 and August 20, Faronics-themed lures reached more than 457 endpoints via emails disguised as invoices, tax documents, or other business files.
Faronics Deploy is a cloud-based endpoint management platform that allows IT administrators to remotely enroll and manage computers, deploy software, and execute scripts.
Researchers at managed detection and response company (MDR) Huntress say that the embedded malicious links lead to a website that profiles potential targets and guides them through a malicious download flow.
If the website is reached from an analysis environment, a decoy routine is activated, such as displaying an error message.
Huntress explains that a potential victim is prompted to download and launch a legitimate, signed Faronics Deploy installer that is disguised as an Adobe document, a reader app, or a plugin update.
Fake Adobe download page
Source: Huntress
When the victim runs the Faronics installer, often named ‘Adobe.exe,’ their computer is enrolled in a Faronics deployment controlled by the attackers.
The threat actor then uses Faronics’ remote-deployment functionality to execute PowerShell scripts on the enrolled computer without further user interaction.
... continue reading