Phishing actors are abusing Faronics Deploy, a legitimate cloud endpoint-management platform, to take administrative control of victim computers and install ConnectWise ScreenConnect, according to BleepingComputer, citing research from managed detection and response firm Huntress. The reported campaign turns a familiar enterprise trust problem into the delivery mechanism. Faronics Deploy is built for IT administrators to enroll and manage computers, deploy software, and execute scripts remotely. In this activity, Huntress says attackers used that same administrative model after persuading users to run a legitimate, signed Faronics installer. Huntress observed the activity between July 21 and August 20, BleepingComputer reports. During that period, Faronics-themed lures reached more than 457 endpoints through emails disguised as invoices, tax documents, or other business files. The malicious links did not simply drop a file immediately. Huntress said the site profiled visitors and guided potential victims through a download flow, while analysis environments could be shown a decoy routine such as an error message. That screening step is consistent with campaigns that try to avoid automated detection, though the provided reporting does not identify the actors behind the operation. If a target continued, they were prompted to download and launch a legitimate Faronics Deploy installer disguised as an Adobe document, reader app, or plugin update, according to the report. Huntress observed the installer often named “Adobe.exe.” Once run, the victim’s computer was enrolled into a Faronics deployment controlled by the attackers. From there, the attackers used Faronics’ remote-deployment capability to execute PowerShell scripts on the enrolled endpoint without additional user interaction, BleepingComputer reports. Huntress said observed scripts used methods including curl, mshta, and msiexec to retrieve or install additional content from attacker-controlled infrastructure or external locations, including GitHub. The end goal described in the report was to install ConnectWise ScreenConnect, another legitimate remote-support tool. BleepingComputer notes that ScreenConnect gave the attackers a separate remote-access mechanism independent of the Faronics deployment, providing interactive control and redundancy if defenders identified and terminated the malicious Faronics deployment or removed its agent. Huntress notified Faronics on August 5, according to BleepingComputer. The report says Faronics confirmed the observed malicious activity, implemented additional anti-abuse measures, and contacted victimized organizations about possible compromise. Huntress said the activity dropped significantly starting August 21, which it viewed as an indication that Faronics’ actions were effective. For administrators, Huntress recommended checking `C:\ProgramData\Faronics\Logs\` for `ScriptRunner.log`, which may preserve names of remotely executed scripts and download URLs. It also pointed to the `ck` parameter in Faronics configuration requests as an indicator tied to the associated customer deployment, and advised organizations to look for ScreenConnect installations where the tool is not normally deployed. Who benefits: Security teams using or monitoring Faronics Deploy benefit from the concrete log locations and indicators reported by Huntress. The guidance is also relevant to teams that inventory remote-support tools such as ScreenConnect. Who's exposed: Organizations whose users received the Faronics-themed lures or ran the disguised installer are the clearest exposed group. Endpoints with unexpected Faronics enrollment activity or unauthorized ScreenConnect installations warrant review.