Published on September 25, 2026
Fake HR Desktop Apps Used to Deploy ScreenConnect for Remote Access
Severity
Medium
Threat actors are impersonating legitimate HR and payroll platforms by offering fake Windows desktop applications that provide attackers with remote access to victims’ systems.
The campaign targets HR and payroll personnel with fraudulent websites claiming to offer desktop versions of HR or payroll services. However, the impersonated providers do not actually offer Windows desktop applications. Once a victim installs the fake application, it silently deploys ConnectWise ScreenConnect, a legitimate remote monitoring and management (RMM) tool, giving the attackers persistent remote access to the compromised system.
The campaign was identified by Allure Security, which found three unnamed U.S.-based HR and payroll platforms being impersonated. The fake websites were created using the legitimate AI-powered application builder Lovable and hosted on Vercel. The download itself was hosted through a GitHub Releases page, further making the attack appear legitimate.
How?
Victims are directed to a professional-looking website offering a supposed Windows desktop application for their HR or payroll provider. The websites are designed to resemble legitimate software download pages and are hidden behind Vercel’s bot challenge, making them more difficult to discover through automated scanning.
After downloading and installing the fake application, the victim is actually installing the legitimate ScreenConnect remote access software. The attackers can then use the RMM tool to remotely access the system and potentially interact with sensitive HR, payroll, and employee information.
The attack does not rely on a conventional malware payload. Instead, it abuses legitimate services and software throughout the infection chain. The fake website is hosted on a legitimate cloud platform, the installer is distributed through GitHub, and the software ultimately installed on the victim’s computer is a legitimate RMM application.
This approach can make the activity more difficult to identify through traditional malware detection because the individual components may appear legitimate when viewed separately.
The campaign highlights how attackers can abuse trusted infrastructure and legitimate remote management software to gain access while avoiding the indicators normally associated with malicious software.
Organizations should verify whether HR and payroll providers actually offer desktop applications before downloading or installing them. Unexpected installations of ScreenConnect or other RMM tools should also be treated as suspicious, particularly when they are not part of the organization’s approved software inventory.
Source
