ESPN'All empires fall': Can Dabo Swinney still get things right at Clemson?ESPN DeportesAtlante vs. Monterrey: alineaciones y probabilidadesThe Jerusalem PostIn Memoriam: Mourning the death of Sunkist Fruit Gems - opinionCNN TürkYapay zeka nasıl devlet sitesine sızdı?PunchLeague of Imams disowns unauthorised Islamic titlesUOLDatafolha/MG: no 2º turno, Flávio vai de 45% a 46% e Lula oscila de 46% para 44%MyJoyOnline‘Development must not always begin from Accra’ — Anwelle Foundation launched in JirapaLenta.ruТрамп допустил возобновление ударов по ИрануInfobaeRoberto Velasco presume ante la ONU cooperación internacional en materia de seguridad y caída de homicidios dolosos en México中国新闻网中国经济面面观|世赛赛场上的“中国技能”Free Malaysia TodayMalaysia komited perangi Islamofobia, kebencian dalam talian自由時報智慧科技競賽登場 新北學生包辦國小組前三名、奪國中組冠軍
The Daily Newsstand · Free, Always
Saturday, September 26, 2026

Crooks use fake desktop apps to fool HR staff into giving them remote access

Translate

Nothing in the attack chain screams malicious software, except none of the impersonated HR and payroll providers actually offers a desktop app

You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual web interface, you grab it.

Unfortunately, the app isn't what it claims to be. Instead, it silently installs ConnectWise's legitimate ScreenConnect software, giving the operator persistent remote access to your PC.

Cybersecurity outfit Allure Security reported the discovery of the campaign Thursday, describing it as the latest evolution in a trend of abusing ScreenConnect and other remote monitoring and management software. This time, the main giveaway is knowing what the vendors actually sell: None offers the Windows app being advertised.

REG AD

According to Allure, the campaign impersonates three unnamed US-based HR and payroll platforms by offering fake desktop clients for those providers’ software. In all three cases, those companies don’t offer a desktop client, meaning all it takes is an unaware HR or payroll clerk tricked by promises of superior performance to potentially expose some incredibly sensitive company data.

REG AD

Allure said that it’s not sure how potential victims are being targeted by the campaign either, but those who have been targeted may not pick up on anything being wrong. Clicking through to the website offering the fake app brings up a legitimate-looking site built using AI app builder Lovable and hosted on Vercel. The site is hidden behind the cloud host’s bot challenge page, meaning scrapers haven’t been able to index it and expose the scam.

Further obscuring the malicious nature of the campaign, the downloads are hosted on a GitHub Releases page, meaning they point to a trusted domain.

Once downloaded and executed, the installer presents the victim with an actual Microsoft installer to make it appear like a legitimate piece of software. It actually installs the Microsoft .NET Desktop Runtime 8.0.26, so it goes through the entire process and shows that an installation completes, but nothing ever pops up, leaving the victim unclear as to where their desktop app went.

That’s not all the installer is doing, of course: It’s also running a quiet, no-interface installer to drop the ScreenConnect client on the victim’s machine.

“The [ScreenConnect] access mode is set to unattended,” Allure notes. “The victim-facing indicators are turned off: no ‘your machine is being controlled’ banner, no system-tray icon, no connection balloon.”

The silent install is also configured to launch on boot, and stay connected across various user sessions, giving the attacker “a quiet, persistent, interactive foothold,” says Allure. 

“Nothing in this chain is malware in the usual sense,” the infosec outfit said. “The page was generated by a legitimate AI builder and served by a legitimate host. The download came from a legitimate code platform. The one window the victim saw belonged to Microsoft. The thing that was installed is a legitimate RMM product, doing what it was designed to do, for someone who was never supposed to have it.” 

In other words, security teams have some work to do before they even check the indicators of compromise that Allure included in its report: Check with HR and payroll vendors to see if they offer a desktop app, and if not alert all members of those teams to this campaign. 

REG AD

For those hoping they haven’t fallen victim, the actual number of victims remains unknown. Allure said the GitHub download counts across the three fake downloads totaled 291 as of its report. Some of those came from Allure’s researchers, and possibly other researchers and sandboxes too, so the download count can’t be used to determine how many victims there are. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.