AI News Feed
Market watch
Cybersecurity

Hackers Use Fake HR and Payroll Desktop Apps to Install Hidden Remote Access Tool

Attackers spoofed US HR and payroll platforms with fake desktop apps that install hidden remote access, Allure says.

Allure said the unidentified attackers spoofed three major US HR and payroll platforms. The researchers believe the platforms were chosen because they normally offer a cloud-based service through a browser rather than a standalone desktop application. That absence became part of the deception: the fake sites offered a desktop client the real vendors do not ship, leaving victims with no legitimate version to compare against the download.

The fake landing pages were built with Lovable, a legitimate AI-powered service that creates websites and landing pages from prompts and requires no technical knowledge, according to the report. The pages copied the brands but added a download button. Clicking it delivered an executable hosted on GitHub Releases, a GitHub feature developers use to publish packaged software versions. Because GitHub Releases is a legitimate service commonly used to host software, the download did not raise suspicion on its own.

The executable was not itself malicious, Allure said, which helped it avoid most antivirus and endpoint protection tools and made installation easy. The file was a modified build of ConnectWise ScreenConnect, a remote desktop and remote IT support platform used by IT departments and managed service providers. ScreenConnect is legitimate, but because it provides remote and often privileged access, it is attractive to attackers.

Allure extracted the client configuration and launch parameters and found the build was set to unattended access. Victim-facing indicators were disabled: no banner saying the machine was being controlled, no system-tray icon and no connection balloon. The result was remote access without any notification to the person using the computer.

The researchers did not identify the attackers or say how successful the campaign was. They also did not specify the exact organizations targeted beyond finance and HR departments. The GitHub downloads page showed 291 downloads, but Allure said that number does not equal 291 victims or successful attacks. Security researchers, sandboxes and other non-victims could account for downloads, and some victims may have detected the attack before suffering damage, making the actual victim count likely much smaller.

The endgame is not known, Allure said, but the researchers pointed to wire fraud as a possibility. "Whoever installs it is the person who runs payroll, and unattended access to that machine is a path to diverting or draining an entire company's payroll," they said. Allure advised companies using cloud payroll or HR platforms to check whether their vendor actually provides a desktop client this week and to tell employees that a download the vendor does not offer is not an upgrade.

Editor's Summary Allure found that attackers spoofed three major US HR and payroll platforms with fake desktop clients built through Lovable, then delivered a modified ScreenConnect build from GitHub Releases. The tool was configured for hidden unattended access, and the campaign recorded about 291 downloads. Allure did not name the attackers or confirm victims, but warned that compromised payroll machines could be used to divert company payments.