“The delivery method varies between scripts, with observed examples using curl or mshta to retrieve additional content, while others invoke msiexec to install payloads hosted on attacker-controlled infrastructure.” Between July 21 and August 20, Faronics-themed phishing lures reached more than 457 endpoints as attackers used a legitimate endpoint-management channel to gain remote control and install additional remote-access software, Huntress reported.
Phishing lures and the malicious download flow
Huntress observed emails disguised as invoices, tax documents, or other business files that embedded links to a site tailored to profile potential victims and guide them through a malicious download flow. If the site was queried from an analysis environment, the page activated decoy routines — for example, displaying an error message — to evade detection. Victims were prompted to download and run a signed Faronics Deploy installer that the attackers disguised as an Adobe document, a reader app, or a plugin update; the installer was frequently named “Adobe.exe.”
How attackers abused Faronics Deploy and installed ScreenConnect
When a victim executed the Faronics installer, their machine was enrolled into a Faronics deployment controlled by the attacker. The adversary then used Faronics’ remote-deployment capability to execute PowerShell scripts on the enrolled host without further user interaction. Those scripts downloaded additional tools from attacker infrastructure and from external locations — including GitHub — and ultimately installed ConnectWise ScreenConnect. Huntress summarized the multi-pronged delivery: “These scripts are subsequently used to install ScreenConnect, establishing an additional remote access mechanism on the compromised endpoint.”
Huntress documented multiple delivery methods within the scripts, including use of curl and mshta to retrieve content, and msiexec to install packages hosted on attacker-controlled infrastructure. By installing ScreenConnect, attackers gained a remote-access channel independent of Faronics: a hands-on interactive control path and redundancy if the malicious Faronics deployment or agent was identified and removed.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildFaronics’ response and the campaign’s measured decline
Huntress notified Faronics of the abuse on August 5. Faronics confirmed the malicious activity and implemented additional anti-abuse measures; the vendor also contacted organizations it believed had been victimized to notify them about potential compromise. According to Huntress, malicious activity dropped significantly beginning August 21, which the researchers interpret as an indication that Faronics’ mitigations had effect.
Indicators, logs, and investigative leads for administrators
Huntress provided concrete artifacts administrators can search for. The ScriptRunner.log file at C:\ProgramData\Faronics\Logs\ may preserve names of remotely executed scripts and download URLs. The company also flagged the ck parameter in Faronics configuration requests as an identifier for the associated customer deployment that can help discover compromised endpoints or malicious accounts. Finally, Huntress recommended looking for ScreenConnect installations in locations where ScreenConnect is not normally deployed.
The advisory underscores an operational truth Huntress highlighted: “Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.” To quantify defensive performance, the Blue Report 2026 — cited by Huntress — measures defenses technique by technique across 338 million simulations run in customer production environments.
What this means for administrators, enterprises, and technologists
- Administrators: Search the specified Faronics log path for ScriptRunner.log and review configuration requests for the ck parameter; look for unexpected ScreenConnect installations.
- Enterprises and procurement leaders: Be aware that legitimate endpoint-management platforms can be abused as delivery channels and that vendor cooperation (as Faronics provided) can materially reduce ongoing abuse.
- Technologists and security teams: Track the different script delivery techniques Huntress observed (curl, mshta, msiexec) and monitor for post-enrollment remote-deployment activity that could indicate an attacker-controlled deployment.
This incident is notable for its use of a legitimate administrative platform to gain programmatic, post-install control and for the rapid effect of vendor-led countermeasures: notification to victimized organizations and built-in anti-abuse changes corresponded with a measurable decline in observed activity. Administrators should treat unexpected enrollments and nonstandard remote-access installations as higher-risk artifacts and prioritize the log locations and request parameters Huntress identified.
Original report: https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/




