Attackers exploit Faronics Deploy tool to plant ScreenConnect remote access
Huntress researchers found phishing campaigns that trick victims into running a disguised but legitimate Faronics Deploy installer, often labeled as an Adobe file, which secretly enrolls their machine into an attacker-controlled management console. From there, attackers run PowerShell scripts to fetch additional tools and install ConnectWise ScreenConnect, giving them persistent remote access. Over 457 endpoints were targeted between July 21 and August 20 using fake invoice and tax-document lures.