Faronics Deploy phishing campaign to install ScreenConnect
Campaign
Summary
Hide ▲
Show ▼
A phishing campaign is abusing Faronics Deploy to enroll victim endpoints and install ConnectWise ScreenConnect, giving attackers remote administrative control and a separate remote-access channel. The activity ran from July 21 to August 20 and used invoice and tax-document lures that reached more than 457 endpoints. Faronics later confirmed the abuse and added anti-abuse measures.
Related Happenings
Faronics Deploy adds anti-abuse measures after confirmed abuse
Security Tool/Service
H score34
First: 01.09.2026 23:53
Last: 01.09.2026 23:53
Sources 1
How related:
Huntress notified Faronics of its findings on August 5, and the vendor confirmed the observed malicious activity, countering it by implementing additional anti-abuse measures.
About this happening:
Faronics tightened Faronics Deploy with additional anti-abuse measures after confirming malicious use of the platform, reducing abuse activity across the service. The...
Faronics Deploy adds anti-abuse measures after confirmed abuse
Security Tool/ServiceHow related: Huntress notified Faronics of its findings on August 5, and the vendor confirmed the observed malicious activity, countering it by implementing additional anti-abuse measures.
About this happening: Faronics tightened Faronics Deploy with additional anti-abuse measures after confirming malicious use of the platform, reducing abuse activity across the service. The...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor Meta
H score14
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor MetaAbout this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
OAuth device-code phishing campaign targeting SaaS accounts
Campaign
H score43
First: 04.04.2026 17:17
Last: 04.04.2026 17:17
Sources 1
About this happening:
A device code phishing campaign now includes NovaCookies, a $320/month adversary-in-the-middle kit that proxies Microsoft 365 sign-ins and steals authenticated ses...
OAuth device-code phishing campaign targeting SaaS accounts
CampaignAbout this happening: A device code phishing campaign now includes NovaCookies, a $320/month adversary-in-the-middle kit that proxies Microsoft 365 sign-ins and steals authenticated ses...
Google Ads tax-search ScreenConnect malvertising campaign
Campaign
H score32
First: 24.03.2026 19:05
Last: 24.03.2026 19:05
Sources 1
About this happening:
A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...
Google Ads tax-search ScreenConnect malvertising campaign
CampaignAbout this happening: A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...
Timeline
-
01.09.2026 23:53 1 articles · 2h ago
Faronics-themed phishing lures enroll endpoints into attacker-controlled Faronics Deploy deployments
Campaign Scope UpdateFaronics-themed phishing emails disguised as invoices, tax documents, or other business files reached more than 457 endpoints and guided targets through a malicious download flow that enrolled victim computers into attacker-controlled Faronics Deploy deployments before scripted follow-on activity installed ConnectWise ScreenConnect.
Show sources
- Hackers abuse Faronics Deploy admin tool to install ScreenConnect — www.bleepingcomputer.com — 01.09.2026 23:53
-
01.09.2026 23:53 2 articles · 2h ago
Huntress alerts Faronics to malicious Faronics Deploy abuse
Initial DisclosureHuntress notified Faronics about the malicious use of Faronics Deploy on August 5, and Faronics confirmed the abuse while adding additional anti-abuse measures.
Show sources
- Hackers abuse Faronics Deploy admin tool to install ScreenConnect — www.bleepingcomputer.com — 01.09.2026 23:53
- Hackers abuse Faronics Deploy admin tool to install ScreenConnect — www.bleepingcomputer.com — 01.09.2026 23:53
-
01.09.2026 23:53 1 articles · 2h ago
Faronics anti-abuse measures coincide with a sharp drop in malicious activity
Mitigation Patch UpdateStarting August 21, malicious activity dropped significantly, suggesting that Faronics' anti-abuse measures disrupted the phishing operation and reduced abusive deployments.
Show sources
- Hackers abuse Faronics Deploy admin tool to install ScreenConnect — www.bleepingcomputer.com — 01.09.2026 23:53