Cyber

Hackers Abuse Faronics Deploy Admin Tool to Install ScreenConnect

Threat actors are weaponizing the legitimate Faronics Deploy endpoint-management platform to deploy ScreenConnect and gain remote access.

·1 min read
Hackers Abuse Faronics Deploy Admin Tool to Install ScreenConnect

Cybersecurity researchers have uncovered a new campaign where malicious actors are abusing legitimate endpoint-management tools for unauthorized access. Specifically, attackers are leveraging the Faronics Deploy platform to infiltrate victim systems.

Phishing actors have found a way to misuse this administrative software to stealthily install the ScreenConnect remote support tool on target computers. Once installed, it grants the attackers persistent remote administrative control over the compromised machines.

While tools like Faronics Deploy are designed to help system administrators efficiently manage workstations, their abuse poses a significant challenge for security teams. Legitimate endpoint tools often bypass standard detection mechanisms because they are trusted software.

This incident underscores the importance for organizations worldwide, including tech sectors in developing regions, to strictly monitor administrative software usage and implement robust endpoint detection and response measures to fend off sophisticated threats.

#Faronics Deploy#ScreenConnect#Kiberxavfsizlik#Fishing#IT xavfsizlik#BleepingComputer

Related articles