Trap in the incoming. A regular account from the accounting department gives computers under the hidden control of criminals

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
915
Deposit
0$
A familiar business email can turn an administrator’s full-time tool into a computer capture channel without exploiting a vulnerability. Huntress found обнаружилиa phishing campaign in which attackers persuaded users to install the legal Faronics Deploy platform, and then deployed ScreenConnect for remote access through it.

From July 21 to August 20, Faronics-related baits met on more than 457 end devices. Letters were disguised as tax documents, accounts, financial statements and invitations. The link led to the site, which collected information about the browser, system, language, time zone and screen of the visitor, after which I decided, show a malicious chain or a safe plug.

Fake pages depicted viewing Adobe document, inviting Zoom, or downloading a file. The victim was offered to launch an allegedly outdated plugin, but the signed installer connected the computer to the Faronics Deploy account under the control of criminals. Having obtained administrative rights, the full-time agent could install programs and execute scripts without new user actions.

Through Faronics Deploy, operators launched PowerShell commands and uploaded additional scripts, including from GitHub. In different variants of the chain, curl, mshta and msiexec were used. The next link was ScreenConnect, which created the second channel of remote control. Legitimate and signed tools helped to mask activity under the usual work of the IT service.

Huntress notified Faronics on August 5. Criminals have registered accounts for fictional organizations and fraudulent domains, and have also captured other people’s accounts. Faronics has introduced additional measures against abuse and has contacted possible victims. Since about August 21, the number of cases detected has dropped dramatically, although experts have not declared the campaign completely completed.

With the unexpected appearance of Faronics Deploy, defenders are advised to isolate the device and save the journal C:\ProgramData\Faronics\Logs\ScriptRunner.log. It can remain the addresses of the running scenarios and traces of the installation of ScreenConnect. Then you need to remove unauthorized controls, check the commands and fixing mechanisms, and when you compromise the account data, change passwords.
 
Top Bottom