Subscribe Sign in

Crooks use fake desktop apps to fool HR staff into giving them remote access

3 min read Rewritten in plain language

Security

Show what we removed Rules applied: A1×2 A3×5 D3×10 D4×4 E3×5 F2×5 all 30 rules
  • Nothing in the attack chain screams malicious software, except none of the impersonated HR and payroll providers offers a desktop app
  • The app isn't what it claims to be.
  • Cybersecurity outfit Allure Security reported the discovery of the campaign Thursday, describing it as the latest evolution in a trend of abusing ScreenConnect and other remote monitoring and management software.
  • According to Allure, the campaign impersonates three unnamed US-based HR and payroll platforms by offering fake desktop clients for those providers’ software.
  • Allure said the GitHub download counts across the three fake downloads totaled 291 as of its report.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

There is nothing in this headline a machine can check against the report: no figure, no name and no quotation.

Nothing was measured here, so nothing is claimed. How this is checked

Read the full reportHide the full report3 min

Nothing in the attack chain screams malicious software, except none of the impersonated HR and payroll providers offers a desktop app

You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual web interface, you grab it.

The app isn't what it claims to be. Instead, it silently installs ConnectWise's ScreenConnect software, giving the operator persistent remote access to your PC.

Cybersecurity outfit Allure Security reported the discovery of the campaign Thursday, describing it as the latest evolution in a trend of abusing ScreenConnect and other remote monitoring and management software. This time, the main giveaway is knowing what the vendors sell: None offers the Windows app being advertised.

According to Allure, the campaign impersonates three unnamed US-based HR and payroll platforms by offering fake desktop clients for those providers’ software. In all three cases, those companies don’t offer a desktop client, meaning all it takes is an unaware HR or payroll clerk tricked by promises of superior performance to potentially expose some sensitive company data.

Allure said that it’s not sure how potential victims are being targeted by the campaign either, but those who have been targeted may not pick up on anything being wrong. Clicking through to the website offering the fake app brings up a legitimate-looking site built using AI app builder Lovable and hosted on Vercel. The site is hidden behind the cloud host’s bot challenge page, meaning scrapers haven’t been able to index it and expose the scam.

Further obscuring the malicious nature of the campaign, the downloads are hosted on a GitHub Releases page, meaning they point to a trusted domain.

Once downloaded and executed, the installer presents the victim with an actual Microsoft installer to make it appear like a piece of software. It installs the Microsoft.NET Desktop Runtime 8.0.26, so it goes through the entire process and shows that an installation completes, but nothing ever pops up, leaving the victim unclear as to where their desktop app went.

That’s not all the installer is doing, of course: It’s also running a quiet, no-interface installer to drop the ScreenConnect client on the victim’s machine.

“The [ScreenConnect] access mode is set to unattended,” Allure notes. “The victim-facing indicators are turned off: no ‘your machine is being controlled’ banner, no system-tray icon, no connection balloon.”

The silent install is also configured to launch on boot, and stay connected across various user sessions, giving the attacker “a quiet, persistent, interactive foothold,” says Allure.

“Nothing in this chain is malware in the usual sense,” the infosec outfit said. “The page was generated by a legitimate AI builder and served by a legitimate host. The download came from a legitimate code platform. The one window the victim saw belonged to Microsoft. The thing that was installed is a legitimate RMM product, doing what it was designed to do, for someone who was never supposed to have it.”

In other words, security teams have some work to do before they even check the indicators of compromise that Allure included in its report: Check with HR and payroll vendors to see if they offer a desktop app, and if not alert all members of those teams to this campaign.

For those hoping they haven’t fallen victim, the actual number of victims remains unknown. Allure said the GitHub download counts across the three fake downloads totaled 291 as of its report. Some of those came from Allure’s researchers, and possibly other researchers and sandboxes too, so the download count can’t be used to determine how many victims there are. ®

You are reading our version, not theirs. This is The Register's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 13.3 22 64 -0.1 50.2
Mundane Readneutralized from The Register 9.3 20 64 -0.1 50.2

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works