Incident
Published 2026-08-31
Verified 2026-09-19

Huntress: phishing abuses Faronics Deploy to chain ScreenConnect remote access

Huntress published on 31 August 2026 that phishing actors abused the legitimate Faronics Deploy endpoint-management platform between 21 July and 20 August 2026, with more than 457 endpoints encountering Faronics-themed lures (invoices, tax documents and similar). Victims were steered to download a signed Faronics Deploy installer disguised as an Adobe document or plugin; once enrolled in an attacker-controlled deployment, operators used Faronics remote script execution (PowerShell via curl, mshta or msiexec) to install ConnectWise ScreenConnect as a second remote-access channel. Huntress notified Faronics on 5 August 2026; Huntress says Faronics added anti-abuse controls and contacted affected organisations, and observed activity drop sharply from 21 August. Defenders should inspect C:\ProgramData\Faronics\Logs\ScriptRunner.log and unexpected ScreenConnect installs, and report suspected abuse to support@faronics.com.

Product
Faronics Deploy; ConnectWise ScreenConnect
Exploited in Australia?
unknown
Patch to
Remove unauthorised Faronics/ScreenConnect enrolments; review ScriptRunner.log; report abuse to Faronics

Primary: Huntress (31 Aug 2026) ยท BleepingComputer (1 Sep 2026)

breaches identity