Phishing Campaign Impersonates Adobe to Trick Users into Installing Faronics Deploy for System Takeover

Views: 42 views

481/69 Thursday, September 3, 2026

Cybersecurity researchers from Huntress detected a phishing campaign impersonating business documents, invoices, or tax documents to target users in organizations. More than 457 computers were targeted between July 21 and August 20. The threat actors abused Faronics Deploy, a legitimate cloud-based endpoint management platform, as the main channel to take control of victims’ machines and as a foothold for secretly installing additional remote control software to maintain long-term access.

In this attack, links attached to phishing emails directed victims to websites impersonating Adobe document-sharing pages. These pages displayed pop-up messages claiming that the document download had been completed and tricked users into opening the file to view its contents. The file was disguised under names such as Adobe.exe or as a plugin updater, but it was actually an installer for Faronics Deploy. Once executed, the victim’s computer was immediately enrolled into a Faronics environment controlled by the threat actors. The attackers then used Faronics’ command execution features to run PowerShell scripts through commands such as curl, mshta, or msiexec, downloading additional tools from attacker-controlled servers or GitHub and installing ConnectWise ScreenConnect as a backup access channel in case the Faronics connection was removed or detected.

After being notified, Faronics implemented additional measures to prevent misuse and coordinated with affected organizations, resulting in a decline in attack activity from August 21 onward. Administrators and organizations seeking to investigate and reduce risk should review the ScriptRunner.log file in C:\ProgramData\Faronics\Logs\ to identify script names and URLs that were executed. They should also inspect the ck parameter in Faronics configuration requests to identify suspicious user accounts or abnormal enrollments, and promptly investigate endpoints where ScreenConnect has been installed without an approved organizational policy to prevent unauthorized system access.

Source: https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/