Allure Security disclosed the campaign on Thursday. It impersonates three unnamed US-based HR and payroll platforms, advertising Windows desktop clients that the real vendors do not offer. The fake websites are built using the AI app builder Lovable and hosted on Vercel, hidden behind the host's bot challenge page to avoid indexing by scrapers. The malicious downloads are hosted on GitHub Releases, leveraging the platform's trusted domain.
When executed, the installer runs a genuine Microsoft .NET Desktop Runtime 8.0.26 installation, showing a legitimate progress window but never opening an app. Behind the scenes, it silently installs ConnectWise's ScreenConnect, a legitimate remote monitoring and management product. The access mode is set to "unattended" with victim-facing indicators disabled — no "your machine is being controlled" banner, no system tray icon, and no connection balloon. The client is configured to launch at boot and maintain persistence across user sessions.
"Nothing in this chain is malware in the usual sense," Allure said. "The page was generated by a legitimate AI builder and served by a legitimate host. The download came from a legitimate code platform. The one window the victim saw belonged to Microsoft. The thing that was installed is a legitimate RMM product, doing what it was designed to do, for someone who was never supposed to have it."
The GitHub download counts for the three fake installers totaled 291 as of Allure's report, though the firm cautioned that its own researchers and sandboxes account for some of those downloads. The actual number of victims remains unknown, as does how targets are being chosen. Allure advises organizations to check with their HR and payroll vendors to confirm whether they offer desktop clients, and to alert staff to the campaign.