TechNewsReel
Live

Attackers Weaponize Faronics Deploy to Install ScreenConnect

Threat actors are abusing a legitimate endpoint-management tool to bypass security detections and maintain remote control over victim systems.

TechNewsReel Newsroom · September 1, 2026

Cybercriminals are leveraging the Faronics Deploy endpoint-management platform to gain unauthorized remote administrative access to victim computers. By hijacking this trusted administrative tool, attackers can bypass security perimeters to install persistent remote-access software.

Reports indicate that attackers utilize the administrative capabilities of Faronics Deploy to push ScreenConnect, a legitimate remote support software, onto compromised systems. Once ScreenConnect is installed, the actors can maintain long-term, persistent control over the affected machines with high-level privileges.

The Mechanics of the Breach

Faronics Deploy is designed for IT administrators to manage software deployment and system configurations across a corporate network. Because the tool is intended for wide-scale administrative changes, it possesses the necessary permissions to execute commands and install software across multiple endpoints simultaneously. When attackers gain control of this platform, they can execute these functions to deploy their own tools while appearing as legitimate administrative activity to many security monitors.

The Danger of Living-off-the-Land

This campaign is a prime example of a "living-off-the-land" (LotL) attack, where legitimate system tools are weaponized for malicious purposes. Because Faronics Deploy is a trusted, signed application, its activity often evades traditional antivirus and Endpoint Detection and Response (EDR) systems that typically flag unsigned or unknown binaries. By using a tool already approved by the organization's security policy, attackers can operate in plain sight, granting them deep and durable access to corporate environments without triggering standard alarms.

Industry Implications

The shift toward LotL techniques highlights a critical gap in traditional signature-based security. When attackers use the very tools meant to protect and manage a network to instead compromise it, the distinction between a routine update and a security breach becomes nearly invisible. This forces organizations to move beyond trusting signed software and instead focus on behavioral analysis—monitoring not just what is running, but why a trusted tool is suddenly deploying remote-access software across the network.

What to Watch

Security teams are advised to monitor Faronics Deploy logs for unauthorized software deployments, specifically the installation of remote management tools like ScreenConnect. While the core mechanism of the attack is confirmed, organizations should remain vigilant for any unusual administrative activity originating from their endpoint management consoles, as these trusted paths remain high-value targets for persistent threat actors.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.