Find notable cyber news and cases, enriched with sources, timelines, and signals.

Faronics Deploy phishing campaign to install ScreenConnect

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

A phishing campaign is abusing Faronics Deploy to enroll victim endpoints and install ConnectWise ScreenConnect, giving attackers remote administrative control and a separate remote-access channel. The activity ran from July 21 to August 20 and used invoice and tax-document lures that reached more than 457 endpoints. Faronics later confirmed the abuse and added anti-abuse measures.

Related Happenings

Faronics Deploy adds anti-abuse measures after confirmed abuse

Security Tool/Service
H score34 First: 01.09.2026 23:53 Last: 01.09.2026 23:53 Sources 1

How related: Huntress notified Faronics of its findings on August 5, and the vendor confirmed the observed malicious activity, countering it by implementing additional anti-abuse measures.

About this happening: Faronics tightened Faronics Deploy with additional anti-abuse measures after confirming malicious use of the platform, reducing abuse activity across the service. The...

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score62 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...

The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster

Threat Actor Meta
H score14 First: 13.07.2026 18:30 Last: 13.07.2026 18:30 Sources 1

About this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...

OAuth device-code phishing campaign targeting SaaS accounts

Campaign
H score43 First: 04.04.2026 17:17 Last: 04.04.2026 17:17 Sources 1

About this happening: A device code phishing campaign now includes NovaCookies, a $320/month adversary-in-the-middle kit that proxies Microsoft 365 sign-ins and steals authenticated ses...

Google Ads tax-search ScreenConnect malvertising campaign

Campaign
H score32 First: 24.03.2026 19:05 Last: 24.03.2026 19:05 Sources 1

About this happening: A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...

Timeline

  1. 01.09.2026 23:53 1 articles · 2h ago

    Faronics-themed phishing lures enroll endpoints into attacker-controlled Faronics Deploy deployments

    Campaign Scope Update

    Faronics-themed phishing emails disguised as invoices, tax documents, or other business files reached more than 457 endpoints and guided targets through a malicious download flow that enrolled victim computers into attacker-controlled Faronics Deploy deployments before scripted follow-on activity installed ConnectWise ScreenConnect.

    Show sources
  2. 01.09.2026 23:53 2 articles · 2h ago

    Huntress alerts Faronics to malicious Faronics Deploy abuse

    Initial Disclosure

    Huntress notified Faronics about the malicious use of Faronics Deploy on August 5, and Faronics confirmed the abuse while adding additional anti-abuse measures.

    Show sources
  3. 01.09.2026 23:53 1 articles · 2h ago

    Faronics anti-abuse measures coincide with a sharp drop in malicious activity

    Mitigation Patch Update

    Starting August 21, malicious activity dropped significantly, suggesting that Faronics' anti-abuse measures disrupted the phishing operation and reduced abusive deployments.

    Show sources