MalwareBleeping Computer
8.0 — CRITICAL
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Phishing actors abused the Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install ScreenConnect, a legitimate remote support software.
⚙️Technical Details
Affected Systems
Faronics Deploy cloud-based endpoint management platform
Attack Vectors
Malicious links in emails disguised as invoices, tax documents, or other business filesEmbedded malicious links leading to a website that profiles potential targets and guides them through a malicious download flow
💥Impact Assessment
Severity: high
Who Is at Risk
Organizations using Faronics Deploy endpoint-management platform
🛡️Recommended Actions
1Check the 'C:\ProgramData\Faronics\Logs' location for a ScriptRunner.log file
2Look for ScreenConnect installations where it is not normally deployed
3Verify the 'ck parameter in Faronics configuration requests'
📦Affected Products
Software: Faronics Deploy
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
