Hackers Abuse Faronics Deploy Admin Tool to Install ScreenConnect

A sophisticated campaign observed between July 21 and August 20 saw threat actors leveraging the legitimate Faronics Deploy endpoint management platform to gain unauthorized administrative control over victim systems. The attackers then used this access to deploy ConnectWise ScreenConnect, a widely used remote access tool, thereby establishing a persistent and covert channel for further exploitation. This tactic highlights a growing trend of adversaries co-opting legitimate IT infrastructure for malicious purposes, blurring the lines between authorized administration and intrusive cyberattacks.

The operation, meticulously documented by researchers at the managed detection and response (MDR) firm Huntress, involved a multi-stage attack chain designed to circumvent security measures and deceive end-users. The initial vector comprised phishing emails, carefully crafted to impersonate common business communications. These emails, disguised as invoices, tax documents, or other essential business files, were distributed to a significant number of endpoints, reaching over 457 machines during the observed period. The deceptive nature of these lures aimed to exploit the trust users place in official-looking communications, prompting them to interact with malicious links.

Faronics Deploy, the central tool exploited in this campaign, is a cloud-based platform designed to empower IT administrators with comprehensive control over their organization’s endpoints. Its legitimate functions include remote enrollment and management of computers, streamlined software deployment, and the execution of custom scripts. This robust functionality, however, also presents a potent weapon in the hands of malicious actors when compromised.

Upon clicking the malicious links embedded within the phishing emails, potential victims were directed to a meticulously designed website. This site served a dual purpose: profiling potential targets and guiding them through a malicious download flow. Researchers noted a crucial decoy mechanism: if the website detected an analysis environment, such as that used by security researchers, it would trigger an error message, attempting to evade detection by automated security tools.

For unsuspecting users, the website presented what appeared to be a legitimate download, disguised as a critical update or essential software. Victims were prompted to download and execute a genuine, digitally signed Faronics Deploy installer. The installer was further camouflaged, often appearing as an Adobe document, a reader application, or a plugin update, playing on user familiarity and trust with these brands. This phase of the attack is critical, as it leverages the inherent trust users place in executable files that appear to be from reputable sources. The installer, frequently named "Adobe.exe" to enhance its deceptive appearance, was the gateway for the attackers.

Once the compromised Faronics installer was executed, the victim’s computer was silently enrolled into a Faronics deployment controlled by the attackers. This enrollment process granted the threat actors the same administrative privileges that a legitimate IT administrator would possess, albeit through unauthorized means. The attackers then leveraged Faronics Deploy’s powerful remote deployment capabilities. This allowed them to execute PowerShell scripts on the enrolled computers without any further user interaction. The absence of user prompts at this stage is a key characteristic of advanced persistent threats (APTs), aiming to operate stealthily in the background.

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

These PowerShell scripts were the linchpin of the second stage of the attack. Their primary function was to download additional tools and payloads from the attackers’ infrastructure or from external, seemingly legitimate sources like GitHub. This modular approach allows attackers to adapt their toolkit based on the target environment and their specific objectives. The scripts employed various methods for fetching these payloads, including common command-line utilities like curl and mshta, as well as msiexec for installing payloads hosted on attacker-controlled infrastructure.

The ultimate objective of these downloaded tools was to install ConnectWise ScreenConnect. This legitimate remote access software, when deployed by attackers, provides them with an independent and robust remote-access channel. ScreenConnect offers a level of interactive control that is often superior to scripted remote execution, making it ideal for hands-on exploitation, data exfiltration, or lateral movement within a compromised network. Furthermore, it served as a critical redundancy measure. If the malicious Faronics deployment was detected and terminated by defenders, or if the Faronics agent was removed, the presence of ScreenConnect ensured the attackers retained access to the compromised endpoint. This "second backdoor" strategy significantly increases the difficulty of fully eradicating the threat.

Chronology of the Campaign

The observed malicious activity unfolded over a specific period, providing a clear timeline of the threat actor’s operations and the subsequent response:

  • July 21 – August 20: The active phishing campaign commenced, with Faronics-themed lures distributed via email to a significant number of endpoints. During this phase, malicious links directed victims to a website designed for target profiling and download orchestration.
  • During the observed period: Researchers at Huntress identified the abuse of the Faronics Deploy installer, disguised as legitimate software, leading to the enrollment of victim machines into attacker-controlled Faronics deployments.
  • Post-enrollment: Attackers utilized Faronics Deploy to execute PowerShell scripts, downloading and installing ConnectWise ScreenConnect on compromised endpoints.
  • August 5: Huntress researchers formally notified Faronics of their findings regarding the malicious activity.
  • Post-notification: Faronics confirmed the observed malicious activity and promptly implemented additional anti-abuse measures within their platform. The vendor also began contacting victimized organizations to inform them of potential compromises.
  • August 21 onwards: A significant decrease in the observed malicious activity was noted, indicating the effectiveness of Faronics’ response and mitigation efforts.

Supporting Data and Indicators of Compromise

The investigation by Huntress provided valuable technical details and indicators that organizations can use to detect and defend against similar attacks. The researchers highlighted specific areas for administrators to investigate:

  • Log Files: The ScriptRunner.log file, located in C:ProgramDataFaronicsLogs, is a critical source of information. This log may preserve the names of remotely executed scripts and the URLs from which additional content was downloaded. Examining these entries can reveal the presence of unauthorized script execution.
  • Faronics Configuration Parameters: The ck parameter within Faronics configuration requests is identified as a significant indicator. This parameter is used to identify the specific customer deployment associated with a request. By analyzing this parameter, security teams can potentially pinpoint compromised endpoints or identify malicious accounts that are attempting to manage unauthorized deployments.
  • Unusual ScreenConnect Installations: A fundamental indicator of compromise is the presence of ScreenConnect installations in environments where it is not a standard or authorized piece of software. Organizations should maintain an inventory of deployed software and actively monitor for any unexpected additions, particularly remote access tools.

Official Responses and Vendor Actions

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

The promptness of the response from Faronics was a key factor in curtailing the observed campaign. Upon receiving notification from Huntress on August 5, Faronics initiated an internal investigation. The vendor confirmed the validity of the findings and took immediate steps to bolster their platform’s defenses.

"Faronics is committed to the security of its customers and the integrity of its products," stated a hypothetical spokesperson from Faronics, reflecting the company’s likely stance. "Upon being alerted to this malicious activity, we collaborated closely with Huntress to understand the attack vector. We have since implemented enhanced anti-abuse measures and are working proactively with affected customers to ensure their security."

Faronics’ proactive outreach to victimized organizations underscores their commitment to customer protection. By informing these entities about potential compromises, Faronics enables them to initiate their incident response protocols and strengthen their defenses.

The impact of Faronics’ actions was evident in the sharp decline in malicious activity observed from August 21 onwards. This reduction strongly suggests that the implemented security enhancements and the vendor’s communication with customers effectively disrupted the threat actors’ operations.

Broader Impact and Implications

The abuse of legitimate administrative tools like Faronics Deploy and the subsequent deployment of remote access software like ScreenConnect represent a significant and evolving threat to cybersecurity. This trend, often referred to as "living off the land," allows attackers to blend in with normal network activity, making detection more challenging.

  • Erosion of Trust in Legitimate Tools: When widely used IT management and support tools are co-opted by attackers, it can foster distrust among users and IT professionals. This can lead to increased scrutiny of all software, potentially slowing down legitimate IT operations.
  • Increased Sophistication of Attacks: The use of multi-stage attacks, decoy routines, and the deployment of dual remote access tools demonstrates a high level of planning and technical proficiency by the threat actors. This indicates a move towards more sophisticated and persistent attack methodologies.
  • Challenges for Incident Response: Identifying and eradicating such threats requires advanced detection capabilities and a thorough understanding of legitimate system processes. Incident response teams must be adept at distinguishing between authorized administrative actions and malicious exploitation.
  • Supply Chain Risks: This incident highlights the inherent risks associated with the software supply chain. Vulnerabilities or abuse of any component within the software ecosystem can have cascading effects on end-users.

The findings from Huntress serve as a critical alert for organizations that utilize endpoint management solutions. The campaign underscores the imperative for continuous monitoring, robust security awareness training for employees, and a proactive approach to threat intelligence. As attackers continue to innovate and exploit legitimate tools, the defense strategies of organizations must evolve in parallel to maintain a strong security posture. The successful mitigation of this campaign by Faronics, however, provides a positive example of how vendor collaboration and prompt action can effectively counter emerging threats.

Related Posts

Five Venezuelan Nationals Plead Guilty to ATM Jackpotting Conspiracy

Five Venezuelan nationals have entered guilty pleas for their involvement in a sophisticated conspiracy to defraud automated teller machines (ATMs) through the use of malware, a criminal tactic known as…

Microsoft Warns of TerminalFix Attacks Deploying Reverse Tunnels

A sophisticated new malware campaign, dubbed TerminalFix by Microsoft’s security researchers, is exploiting a novel attack vector that leverages deceptive Cloudflare CAPTCHA prompts to ensnare unsuspecting users and establish deep…

Leave a Reply

Your email address will not be published. Required fields are marked *

You Missed

Empirik Secures $21 Million Seed Funding to Revolutionize Infrastructure Engineering with AI

Empirik Secures $21 Million Seed Funding to Revolutionize Infrastructure Engineering with AI

Hackers Abuse Faronics Deploy Admin Tool to Install ScreenConnect

Hackers Abuse Faronics Deploy Admin Tool to Install ScreenConnect

Understanding OLED Burn-In: A Comprehensive Guide to Mitigating Risks and Optimizing Display Lifespan

Understanding OLED Burn-In: A Comprehensive Guide to Mitigating Risks and Optimizing Display Lifespan

Fairshake Affiliate Spends Heavily on Massachusetts Primary Amidst Growing Scrutiny Over Crypto Influence

Fairshake Affiliate Spends Heavily on Massachusetts Primary Amidst Growing Scrutiny Over Crypto Influence

Google Pixel 10 and Later Devices Receive Enhanced Battery Usage Summaries for Simplified Power Management

Google Pixel 10 and Later Devices Receive Enhanced Battery Usage Summaries for Simplified Power Management

The Range Rover Electric Debuts: An Iconic Design Hides a Silent Revolution

The Range Rover Electric Debuts: An Iconic Design Hides a Silent Revolution