Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Executive Summary

Phishing actors exploit the legitimate Faronics Deploy endpoint‑management platform to gain remote administrative control over victim machines. Once inside, they install the ScreenConnect remote support software, enabling attackers to maintain persistent access and exfiltrate data. The technique demonstrates how trusted tools can be weaponized for stealthy lateral movement.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-01T20:53:23+00:00 - Category: threat-intel

Original Description: Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]

"Worry often gives a small thing a big shadow."

— Swedish proverb
Source: Bleeping Computer