Hackers Abuse Faronics Deploy Admin Tool to Install ScreenConnect
Phishing campaigns leverage legitimate endpoint-management software for unauthorized remote access

Key Takeaways
- Threat actors are abusing the Faronics Deploy endpoint-management platform for unauthorized remote access.
- The abuse facilitates the installation of ScreenConnect remote support software without user consent.
- The abuse was first reported on September 1, 2026, via BleepingComputer.
- No specific vulnerability in Faronics Deploy has been identified; the attack leverages phishing and administrative capabilities.
- Mitigation recommendations include verifying legitimacy of administrative actions, monitoring for unauthorized ScreenConnect installations, and phishing awareness training.
Quick answers
- What happened?
- Security researchers report that threat actors are abusing the Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. The abuse was first highlighted by BleepingComputer on September 1, 2026. No specific vulnerability in Faronics Deploy itself has been identified; instead, attackers are using phishing to exploit the administrative capabilities of the tool.
- Which products are affected?
- Faronics Deploy, ScreenConnect
- What should defenders do?
- Verify legitimacy of Faronics Deploy administrative actions; monitor for unauthorized ScreenConnect installations; implement phishing awareness training and user education; restrict administrative privileges for Faronics Deploy where possible.
According to a report published by BleepingComputer, phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. The abuse allows attackers to achieve persistent remote access to compromised systems. The report indicates that the abuse was first observed on September 1, 2026. Faronics Deploy is a legitimate endpoint-management tool designed for IT administrators to deploy software and configurations across networks. The abuse of such management tools in phishing campaigns is a confirmed attack vector, though specific technical details of the exploitation method require further verification. The report notes that no specific patch has been issued for Faronics Deploy in relation to this abuse; instead, security recommendations focus on verifying the legitimacy of Faronics Deploy administrative actions, monitoring for unauthorized ScreenConnect installations, and implementing phishing awareness training. The actors behind the abuse are described as phishing attackers, but the exact delivery mechanism, specific victim organizations affected, and whether Faronics Deploy itself has a vulnerability being exploited or is being used legitimately but maliciously remain unverified.
Security Details
Abuse of legitimate Faronics Deploy endpoint-management platform via phishing campaigns to gain remote administrative control and install ScreenConnect remote support software. No specific CVE or vulnerability in Faronics Deploy identified; exploitation relies on social engineering and administrative privileges.
Affected products
Faronics Deploy, ScreenConnect
Mitigation
Verify legitimacy of Faronics Deploy administrative actions; monitor for unauthorized ScreenConnect installations; implement phishing awareness training and user education; restrict administrative privileges for Faronics Deploy where possible.
Sources
BleepingComputer
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Sep 1, 2026 · 20:53
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




