CuraSec

Act active

Hackers abuse Faronics Deploy to silently install ScreenConnect RAT

2026-09-02 15:05 UTC · BleepingComputer · read the source ↗ #remote-access#phishing#endpoint
  • Engineer — Learn: No CVE or patch involved — attackers are abusing a legitimate admin tool’s functionality. Review whether Faronics Deploy is in your environment and whether its deployment permissions are appropriately scoped.
  • SOC/IR — Act: Hunt for unexpected ScreenConnect installations originating from Faronics Deploy processes; build detections for remote-management tool deployments not initiated by IT change management workflows.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.