Faronics Deploy phishing attack installs ScreenConnect

Published August 25, 2026

Attackers are tricking people into installing a real IT management tool called Faronics Deploy, disguised as an Adobe file, then using it to take remote control of the computer and install a second remote access program called ScreenConnect.

Report priority
Medium
Targets
ConnectWise ScreenConnect

How it works

A phishing email with an invoice or tax-document lure links to a fake Adobe download page that tricks the victim into running a real, digitally signed Faronics Deploy installer named something like Adobe.exe, which silently enrolls the computer into an attacker-controlled Faronics deployment that then runs PowerShell scripts to install ScreenConnect.

What to do

Check whether C:\ProgramData\Faronics\Logs\ contains a ScriptRunner.log file, which can show remotely executed scripts from an unauthorized Faronics enrollment, and look for an unexpected Faronics Deploy or ScreenConnect installation on company computers.

Admins should watch for Faronics's compromise notifications, review the ScriptRunner.log for unauthorized script activity, and remove any unrecognized Faronics or ScreenConnect enrollment. Faronics has already added anti-abuse measures that Huntress says sharply cut this activity after August 21.

Technical details

Affected software: ConnectWise ScreenConnect

An employee gets an email disguised as an invoice or tax document with a download link. The link leads to a fake Adobe page that serves a real Faronics Deploy installer renamed Adobe.exe. Running it enrolls the computer into a Faronics deployment the attacker controls, which then runs a script that installs ConnectWise ScreenConnect, giving the attacker a second way to remotely access the machine.

Huntress observed a phishing campaign abusing Faronics Deploy, a legitimate cloud endpoint-management product, as an initial-access and persistence mechanism. Victims are lured through a fingerprinting gate (decoy behavior in analysis environments) into running a signed Faronics installer disguised as Adobe software. Enrollment in an attacker-controlled Faronics tenant lets the actor push PowerShell via Faronics's own remote script execution, using curl, mshta, or msiexec to fetch payloads from attacker infrastructure or GitHub, ultimately installing ConnectWise ScreenConnect as a redundant remote-access channel. Faronics was notified August 5, confirmed the abuse, added anti-abuse controls, and contacted affected organizations; observed activity dropped sharply after August 21.