Security News

Fake HR Desktop Apps Trick Staff Into Handing Over Remote Access

The Register · 26 Sept 2026
Key Takeaway Remind HR and payroll staff to only download software from official vendor websites, and treat any unexpected 'desktop app' offer with suspicion, especially if the provider only operates via a web browser.

Security researchers at Allure Security have uncovered a campaign targeting HR and payroll staff with fake desktop applications. The scam impersonates three US-based HR and payroll platforms, none of which actually offer a Windows desktop app, and lures employees with the promise of a faster alternative to the usual web portal.

Once downloaded, the fake installer displays a legitimate-looking Microsoft installation process, appearing to install the .NET Desktop Runtime. In reality, it quietly installs ConnectWise's ScreenConnect software in the background, giving attackers persistent remote access to the victim's computer. Because ScreenConnect is a legitimate, widely used remote monitoring tool, the intrusion can be difficult to detect.

The campaign is designed to avoid suspicion at every step. The fake download site is built with a legitimate AI app builder and hosted behind a bot-blocking challenge page, preventing security scanners from indexing it. The malicious files themselves are hosted on GitHub Releases, a trusted platform, making the download link appear safe. Allure Security has not yet confirmed how victims are being directed to the fake sites in the first place.

remote access trojan HR security social engineering ScreenConnect abuse SMB cybersecurity

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.