ZeroHour
Huntresspublished ()ingested

Daisy-Chaining Trust: Investigating Faronics Deploy Abuse

mediumThreat actor exploited in the wildimportance 55
AI summary · glm-5.3-flash

Actors abuse Faronics Deploy in phishing campaigns to run PowerShell and deploy ScreenConnect while evading detection with trusted tools.

Huntress investigated attacks in which threat actors abuse Faronics Deploy, a legitimate remote management tool, as part of phishing-driven intrusions. The chain uses the trusted deployment tool to launch PowerShell commands and deploy ScreenConnect for remote access. Leveraging signed, legitimate software helps the actors blend in and evade detection.

  • Faronics Deploy abused as a trusted execution channel in intrusions
  • Phishing used as initial delivery vector
  • ScreenConnect deployed for persistent remote access
  • LotL abuse complicates detection for defenders
Full article

Bad actors are abusing Faronics Deploy in phishing campaigns to run PowerShell, deploy ScreenConnect, and evade detection by using trusted tools.

This source does not provide full text. Read it at huntress.com.