{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/faronics-deploy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Faronics Deploy"],"_cs_severities":["rumour"],"_cs_tags":["persistence","remote-access","execution","privilege-escalation"],"_cs_type":"rumour","_cs_vendors":["Faronics"],"content_html":"\u003cp\u003eSecurity researchers have identified a campaign involving the abuse of Faronics Deploy, a cloud-based IT management and endpoint administration platform. Attackers who gain unauthorized access to the Faronics Deploy management console leverage the platform's legitimate \u0026quot;Deploy\u0026quot; and \u0026quot;Scripting\u0026quot; features to push malicious payloads and administrative commands to registered endpoints. Because these actions are executed by the legitimate Faronics management agent (typically running with elevated system-level privileges), the activity often appears as benign administrative traffic. This technique allows adversaries to establish long-term persistence, move laterally, and deploy additional tooling across an organization without triggering traditional security alerts that focus on external initial access. The lack of anomalous process behavior, combined with the trusted nature of the management agent, makes this a high-impact vector for organizations relying on centralized administration tools.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains unauthorized access to a Faronics Deploy management console (e.g., via stolen credentials or session hijacking).\u003c/li\u003e\n\u003cli\u003eAttacker logs into the console and identifies target endpoints within the management scope.\u003c/li\u003e\n\u003cli\u003eAttacker uses the \u0026quot;Scripting\u0026quot; or \u0026quot;Software Deployment\u0026quot; function to upload a malicious script or executable.\u003c/li\u003e\n\u003cli\u003eThe Faronics Deploy cloud console sends a task signal to the Faronics agent residing on the target Windows endpoint.\u003c/li\u003e\n\u003cli\u003eThe Faronics agent process on the endpoint receives the instruction to execute the payload.\u003c/li\u003e\n\u003cli\u003eThe agent spawns a child process (typically cmd.exe or powershell.exe) to execute the malicious script or binary.\u003c/li\u003e\n\u003cli\u003eThe malicious code runs with SYSTEM privileges on the host to establish persistence or exfiltrate data.\u003c/li\u003e\n\u003cli\u003eThe agent reports task success back to the Faronics console, maintaining the illusion of legitimate administration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of Faronics Deploy allows attackers to bypass perimeter security, achieve full remote control over enterprise endpoints, and deploy ransomware or information stealers. Because the agent executes with SYSTEM privileges, attackers effectively inherit total control over all managed assets, leading to significant risk of data exfiltration and widespread operational disruption within the targeted corporate environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring of the Faronics management agent to detect suspicious sub-processes or unexpected execution patterns.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict access to the Faronics Deploy management console to authorized personnel only, enforcing multi-factor authentication for all sessions.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for the Faronics agent process spawning interactive shells like cmd.exe or powershell.exe.\u003c/li\u003e\n\u003cli\u003eAudit the \u0026quot;Scripts\u0026quot; library and recent deployment tasks within the Faronics console to identify unauthorized or anomalous administrative activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T05:07:13Z","date_published":"2026-09-02T05:07:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-faronics-deploy-abuse/","summary":"Threat actors are exploiting compromised Faronics Deploy management consoles to push malicious scripts and binaries, enabling unauthorized remote code execution and persistence across managed enterprise endpoints.","title":"Abuse of Faronics Deploy for Remote Execution and Persistence","url":"https://feed.craftedsignal.io/briefs/2026-09-faronics-deploy-abuse/"}],"language":"en","title":"CraftedSignal Threat Feed - Faronics Deploy","version":"https://jsonfeed.org/version/1.1"}