Fake HR desktop apps deliver silent remote access via ScreenConnect, researchers warn

Allure Security says attackers impersonate three US HR and payroll platforms with AI-built sites and GitHub-hosted installers

By LineZotpaper
Published
Read Time2 min
Cybersecurity researchers have uncovered a campaign that tricks HR and payroll staff into installing a fake desktop app, only to silently grant attackers persistent remote control of their workstations.

Allure Security disclosed the campaign on Thursday. It impersonates three unnamed US-based HR and payroll platforms, advertising Windows desktop clients that the real vendors do not offer. The fake websites are built using the AI app builder Lovable and hosted on Vercel, hidden behind the host's bot challenge page to avoid indexing by scrapers. The malicious downloads are hosted on GitHub Releases, leveraging the platform's trusted domain.

When executed, the installer runs a genuine Microsoft .NET Desktop Runtime 8.0.26 installation, showing a legitimate progress window but never opening an app. Behind the scenes, it silently installs ConnectWise's ScreenConnect, a legitimate remote monitoring and management product. The access mode is set to "unattended" with victim-facing indicators disabled — no "your machine is being controlled" banner, no system tray icon, and no connection balloon. The client is configured to launch at boot and maintain persistence across user sessions.

"Nothing in this chain is malware in the usual sense," Allure said. "The page was generated by a legitimate AI builder and served by a legitimate host. The download came from a legitimate code platform. The one window the victim saw belonged to Microsoft. The thing that was installed is a legitimate RMM product, doing what it was designed to do, for someone who was never supposed to have it."

The GitHub download counts for the three fake installers totaled 291 as of Allure's report, though the firm cautioned that its own researchers and sandboxes account for some of those downloads. The actual number of victims remains unknown, as does how targets are being chosen. Allure advises organizations to check with their HR and payroll vendors to confirm whether they offer desktop clients, and to alert staff to the campaign.

§

Analysis

Why This Matters

  • HR and payroll systems hold highly sensitive data — employee PII, benefits and salary information — making a successful foothold potentially damaging.
  • The attack abuses legitimate tools and platforms (ScreenConnect, GitHub, Vercel, Microsoft), so conventional malware detection may not flag it.
  • With 291 downloads recorded and no reliable victim count, affected organisations may not know they have been compromised; verifying vendor offerings is an immediate step.

Background

Remote monitoring and management (RMM) tools are widely used by IT teams for legitimate support, but they have increasingly become targets for abuse because they are signed, trusted and capable of deep system access. In this campaign, the attacker chain is built entirely from legitimate components — an AI-built website, a trusted code-hosting platform, a Microsoft installer and a commercial RMM product — making it difficult for users and automated scanners to distinguish from normal software installation.

Key Perspectives

Allure Security (researchers): The firm highlights that nothing in the chain is malware in the traditional sense, which is precisely what makes it dangerous. It recommends that HR and payroll teams confirm with their vendors whether a desktop client actually exists and warn staff about the campaign. Impersonated vendors (unnamed): The three US HR and payroll platforms affected do not offer desktop clients, yet their brands are being used to lend credibility to the scam. They face the challenge of responding to an attack that could erode customer trust, though none has been publicly identified or reported as commenting. Critics/Skeptics: The download count of 291 is modest and includes researcher traffic and sandboxes, so the real number of victims may be low. The targeting method is still unknown, and it is not yet clear how successful the campaign has been — or how widely it may spread.

What to Watch

  • Whether security teams act on the indicators of compromise included in Allure's report and whether the fake domains and GitHub releases are taken down.
  • Whether any of the three impersonated vendors issues a public alert or advisory to their customers.
  • Whether similar fake-desktop-app campaigns emerge using other RMM tools or targeting different departments, such as finance or IT helpdesks.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.