A wave of attacks targeting small and medium businesses has exposed a disturbing trend: cybercriminals are no longer always breaking down the front door. Instead, they are walking in through tools your own IT team already trusts. Recent incidents involving the Faronics Deploy platform — a legitimate software deployment and device management tool — show attackers abusing admin tools to quietly install ScreenConnect, a remote desktop application, giving them persistent, hidden access to business systems. If you manage a business and rely on any kind of IT administration software, this story matters to you.
What Happened and Why It Should Concern SMBs
Faronics Deploy is a well-regarded tool used by schools, businesses, and IT teams to remotely manage and push software to computers across a network. In the attacks being reported, threat actors gained access to the Faronics Deploy console — likely through stolen credentials or exposed login portals — and then used its own legitimate software-pushing capabilities to silently install ScreenConnect across connected devices.
ScreenConnect, now known as ConnectWise ScreenConnect, is itself a legitimate remote access tool used by thousands of IT support teams every day. That is precisely what makes this attack so effective. There is no obvious malware. No unusual-looking executable. Just a trusted tool, installed by another trusted tool, operating in the background. By the time anyone notices something is wrong, the attacker may have had weeks or months of quiet access.
How Attackers Get Into Admin Tools in the First Place
This is where credential exposure becomes the critical weak point for SMBs. Admin consoles like Faronics Deploy, RMM platforms, and cloud management dashboards are high-value targets. Attackers do not need to find a zero-day vulnerability if they can simply log in with a stolen username and password.
Those credentials typically come from three sources. First, data breaches — when a service your employees use gets compromised, their email and password combinations end up in breach databases circulating on dark web forums. Second, infostealer malware — software that silently harvests saved passwords from browsers and applications, then sells those credentials in bulk on dark web markets. Third, credential stuffing — automated tools that test leaked username and password pairs against business login portals until something works.
For SMBs, the problem is compounded by the fact that employees often reuse passwords across personal and work accounts, and that IT admin tools frequently lack multi-factor authentication enforcement by default. One recycled password, one exposed credential from a breach two years ago, can be enough.
What Persistent Remote Access Actually Means for Your Business
Once an attacker has installed a remote access tool like ScreenConnect through an abused admin platform, they effectively have an open door into your network. They can browse file systems, harvest sensitive documents, monitor user activity, deploy ransomware at a time of their choosing, or sell that access on dark web markets to other criminal groups.
The particularly damaging aspect of this type of attack is its patience. Attackers with persistent access often spend weeks doing reconnaissance — learning your business, identifying your most valuable data, and waiting for the right moment. By the time ransomware is deployed or data is exfiltrated, the initial breach may be ancient history and extremely difficult to trace.
For an SMB without a dedicated security operations team, detecting this kind of stealthy intrusion is genuinely hard. Standard antivirus tools will not flag ScreenConnect as malicious because it is not malicious software. It is the context of its installation that is the problem.
Practical Steps to Reduce Your Exposure Right Now
The most immediate action any business can take is to audit what credentials are already exposed. If a username and password associated with your IT admin tools, your team's email accounts, or your cloud platforms has already appeared in a breach database or infostealer dump, you are already at risk — whether you know it or not.
Beyond that, enforce multi-factor authentication on every admin console without exception. Restrict login access to known IP ranges where possible. Review what software deployment tools are doing on your network and who has access to them. Treat your admin tools with the same level of scrutiny you would apply to your banking portal.
Admin tool abuse is not a theoretical threat. It is an active, growing attack vector that disproportionately affects SMBs because attackers know that smaller organisations are less likely to be monitoring for it. Understanding where your credentials are exposed is the first step toward closing that gap. Run a free audit at breachrr.com/audit to find out what information about your business is already out there — before an attacker uses it against you.
Want to see if your company is exposed?