Crooks use fake desktop apps to fool HR staff into giving them remote access
Nothing in the attack chain screams malicious software, except none of the impersonated HR and payroll providers actually offers a desktop app
HR staff in a company were tricked into downloading a fake desktop application that appeared to be a faster alternative to the usual web interface. The app, however, installed legitimate ScreenConnect software, granting the operator persistent remote access to the user's PC. Allure Security, a cybersecurity firm, reported the campaign, stating that it is the latest in a trend of abusing remote monitoring and management software.
The attackers impersonated three unnamed US-based HR and payroll platforms by offering fake desktop clients for their software. None of these companies actually provide a desktop client, making it easy for unsuspecting HR or payroll clerks to be deceived. The campaign's website, built using AI and hosted on Vercel, featured an AI-generated page that appeared legitimate.
The download was hosted on a GitHub Releases page, giving it an air of legitimacy. Upon execution, the installer displayed a Microsoft .NET Desktop Runtime 8.0.26 installation, while simultaneously dropping the ScreenConnect client in the background. The ScreenConnect access was set to unattended, meaning no visual indicators were displayed, and the installer launched on boot, maintaining a persistent connection across user sessions. The attackers have not yet disclosed how many victims they have, as the download count is unknown.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.