Attackers exploit admin tools and unpatched vulnerabilities to gain unauthorized access to corporate networks.
Security researchers have uncovered a troubling new attack pattern where cybercriminals are taking advantage of legitimate IT management software to break into company networks. The scheme involves exploiting previously unknown security gaps in networking equipment, then using trusted administrative tools to install unwanted remote access software that gives hackers complete control over affected systems.
Think of it like this: a burglar finds an unlocked door (the security gap), gets inside your house (the network), then uses your own toolbox (the admin software) to set up permanent ways back in whenever they want (the remote access tool).
The campaign targets companies using SonicWall remote access equipment โ devices that allow employees to connect to company networks from outside the office. Researchers discovered that attackers can chain together multiple security flaws in these devices, creating a pathway to run malicious code. Once inside, the criminals deploy a deployment tool called Faronics Deploy, which is normally used by IT teams to manage computers across an organization. However, in the hands of attackers, this trusted tool becomes a weapon to install ScreenConnect, a legitimate remote support application that cyber criminals can abuse to maintain long-term access to stolen networks.
The concerning part is that this approach uses tools and applications that security software often trusts by default, making the attack much harder to detect.
This discovery represents a shift in how sophisticated attackers operate. Rather than creating entirely new malicious software, they're stacking together existing vulnerabilities and legitimate tools like building blocks. This method is cheaper, faster, and more effective than traditional hacking approaches. It also means that companies relying on standard security defenses might miss these attacks entirely, since the tools being misused are normally considered safe.
For large organizations, this creates a particularly dangerous situation: network administrators trust these tools to function normally, making it easier for criminals to hide their activities in plain sight.
If your company uses SonicWall remote access equipment or similar networking devices, this threat is relevant to you. A successful attack could give criminals access to:
The ripple effects matter too. One compromised network can become a launching point for attacks against other organizations, business partners, and customers.
Organizations should take immediate action:
Bottom line: When legitimate tools become attack weapons, the best defense is staying current with security updates and maintaining vigilant monitoring of network activity.
Companies that act quickly to patch their systems and audit their networks can significantly reduce their exposure to this emerging threat.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters โ