Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
Cybersecurity Classified by Officially
Threat actors are abusing Faronics Deploy, a legitimate endpoint management platform, to execute attacker-controlled PowerShell after phishing victims install the software.
During a one-month period, Huntress saw more than 457 endpoints encountering Faronics-related lures.
In observed cases, threat actors chained Faronics Deploy to ScreenConnect, blending malicious remote access activity into trusted software workflows.
Faronics artifacts, such as ScriptRunner.log and the ck deployment identifier, may help defenders investigate incidents.
Acknowledgments: Special thanks to Ben Nahorney and Aaron Deal for their contributions to this investigation and writeup.
Huntress has identified a surge in phishing campaigns that abuse Faronics Deploy, with more than 457 endpoints encountering Faronics-related lures between July 21 and August 20. Huntress reported this activity to the Faronics support team on August 5. Starting on August 21, we observed the activity drop dramatically as they implemented new measures to disrupt threat actors.
Faronics Deploy is a legitimate endpoint management platform for remotely deploying software and executing scripts across managed devices. By chaining legitimate software, attackers are leveraging Faronics to execute malicious PowerShell scripts and subsequently deploy ScreenConnect, effectively blending in with trusted business workflows. This post details the attack chain, provides key forensic artifacts such as the ScriptRunner.log, and explains how the ck identifier can be used to cluster malicious deployments and track infrastructure.
In the incidents observed by Huntress, victims are initially sent phishing emails themed around routine business activities, including tax documents, invoices, financial records, invitations, and other documents that require the recipient's attention.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/faronics-deploy-abuse
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:52
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/faronics-deploy-abuse