Phishing actors are abusing the legitimate Faronics Deploy admin platform to gain remote control of victim PCs and install ScreenConnect. Learn how this attack works and how to defend your business.
You might think that remote access tools are only a threat when they're shady, off-brand downloads. But what happens when cybercriminals start hijacking software that IT teams actually trust? That's exactly what's unfolding right now.
Security researchers have spotted phishing actors abusing Faronics Deploy—a legitimate endpoint-management platform—to quietly gain remote administrative control over victim computers. Once they're in, they drop ScreenConnect, a well-known remote support tool, onto the system. The scary part? Everything looks legitimate because the tools themselves are real.
### The Attack Chain: How It Works
Let's break this down step by step, because understanding the mechanics is your first line of defense.
1. **The Bait:** A phishing email arrives, often posing as an invoice, a security alert, or a routine IT notice. It contains a link or attachment that triggers the Faronics Deploy agent installation.
2. **The Hook:** Because Faronics Deploy is a signed, legitimate application, it slips past many traditional security filters. The victim unknowingly installs the admin agent.
3. **The Payload:** The attacker, now with administrative privileges through the compromised console, silently installs ScreenConnect. This gives them a persistent, remote backdoor into the machine.
4. **The Goal:** From here, they can steal credentials, move laterally across your network, or deploy ransomware. The remote control is just the beginning.
### Why This Is So Dangerous
This isn't just another malware strain. It's a fundamental abuse of trust. Most endpoint protection platforms (EPP) and firewalls are configured to allowlist known remote admin tools. Why? Because your own IT department probably uses them.
When an attacker uses the same toolset, they're essentially wearing a disguise that your security stack is trained to ignore. It's like a burglar using a locksmith's van and uniform to get into a gated community. The guards wave them through because they look the part.
### What Can You Do to Protect Your Business?
If you're running a business in the United States, you can't just rely on antivirus software anymore. You need a layered defense strategy that questions everything—even the tools you trust.
Here are a few practical steps you can take today:
- **Audit Your Allowlists:** Review your application control policies. Are you allowing tools like ScreenConnect or Faronics Deploy for everyone? Restrict them to specific, named IT admins only.
- **Enable Multi-Factor Authentication (MFA):** This is non-negotiable. Even if an attacker gets the admin credentials, MFA can stop them from actually logging into the remote control console.
- **Monitor for Anomalies:** Watch for new remote control sessions starting outside of business hours or from unusual IP addresses. Your SIEM or log management tool should flag this.
- **Train Your Staff:** Phishing is the entry point. Run regular simulations that test your team's ability to spot suspicious emails, especially those that ask them to install software or click on IT-related links.
> "The most dangerous threats aren't the ones that look scary. They're the ones that look familiar."
### The Bigger Picture: Trust but Verify
This incident highlights a growing trend in cybercrime: living off the land. Attackers are moving away from writing custom malware and instead are abusing built-in tools and legitimate software. It's cheaper, more effective, and much harder to detect.
For IT professionals and business owners, the takeaway is clear. You need to shift your mindset from "block the bad stuff" to "verify the good stuff." Zero-trust architecture isn't just a buzzword; it's a survival strategy.
Start by asking yourself a simple question: Does every employee need remote access software installed on their machine? If the answer is no, then don't let it be there. Remove unused tools, enforce strict policies, and always question why a piece of software is running.
### Final Thoughts
Staying ahead of these threats requires constant vigilance. But it also requires the right tools for the job. While you're locking down your endpoints, it's worth considering how you manage your own online identities and browser sessions—especially if you're juggling multiple accounts for marketing, sales, or ad verification.
A secure, isolated browsing environment can add another layer of separation between your personal identity and your business operations. It's not about paranoia; it's about compartmentalizing risk.
Stay safe out there. The attackers are getting smarter, but so are we.