<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Faronics - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/faronics/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 05:07:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/faronics/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Abuse of Faronics Deploy for Remote Execution and Persistence</title><link>https://feed.craftedsignal.io/briefs/2026-09-faronics-deploy-abuse/</link><pubDate>Wed, 02 Sep 2026 05:07:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-faronics-deploy-abuse/</guid><description>Threat actors are exploiting compromised Faronics Deploy management consoles to push malicious scripts and binaries, enabling unauthorized remote code execution and persistence across managed enterprise endpoints.</description><content:encoded><![CDATA[<p>Security researchers have identified a campaign involving the abuse of Faronics Deploy, a cloud-based IT management and endpoint administration platform. Attackers who gain unauthorized access to the Faronics Deploy management console leverage the platform's legitimate &quot;Deploy&quot; and &quot;Scripting&quot; features to push malicious payloads and administrative commands to registered endpoints. Because these actions are executed by the legitimate Faronics management agent (typically running with elevated system-level privileges), the activity often appears as benign administrative traffic. This technique allows adversaries to establish long-term persistence, move laterally, and deploy additional tooling across an organization without triggering traditional security alerts that focus on external initial access. The lack of anomalous process behavior, combined with the trusted nature of the management agent, makes this a high-impact vector for organizations relying on centralized administration tools.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains unauthorized access to a Faronics Deploy management console (e.g., via stolen credentials or session hijacking).</li>
<li>Attacker logs into the console and identifies target endpoints within the management scope.</li>
<li>Attacker uses the &quot;Scripting&quot; or &quot;Software Deployment&quot; function to upload a malicious script or executable.</li>
<li>The Faronics Deploy cloud console sends a task signal to the Faronics agent residing on the target Windows endpoint.</li>
<li>The Faronics agent process on the endpoint receives the instruction to execute the payload.</li>
<li>The agent spawns a child process (typically cmd.exe or powershell.exe) to execute the malicious script or binary.</li>
<li>The malicious code runs with SYSTEM privileges on the host to establish persistence or exfiltrate data.</li>
<li>The agent reports task success back to the Faronics console, maintaining the illusion of legitimate administration.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful abuse of Faronics Deploy allows attackers to bypass perimeter security, achieve full remote control over enterprise endpoints, and deploy ransomware or information stealers. Because the agent executes with SYSTEM privileges, attackers effectively inherit total control over all managed assets, leading to significant risk of data exfiltration and widespread operational disruption within the targeted corporate environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize monitoring of the Faronics management agent to detect suspicious sub-processes or unexpected execution patterns.</p>
<ul>
<li>Restrict access to the Faronics Deploy management console to authorized personnel only, enforcing multi-factor authentication for all sessions.</li>
<li>Implement monitoring for the Faronics agent process spawning interactive shells like cmd.exe or powershell.exe.</li>
<li>Audit the &quot;Scripts&quot; library and recent deployment tasks within the Faronics console to identify unauthorized or anomalous administrative activity.</li>
</ul>
]]></content:encoded><category domain="severity">rumour</category><category domain="type">rumour</category><category>persistence</category><category>remote-access</category><category>execution</category><category>privilege-escalation</category></item></channel></rss>