Allure Security found fake desktop installers for three US payroll and HR platforms that never offered one, and the files dropped ScreenConnect on the victim machine. The lure is aimed at the people who actually run payroll, because control of that workstation can become control over the pay run.
The installer first shows a real Microsoft-signed .NET Desktop Runtime setup, then quietly launches ScreenConnect in the background with unattended access turned on. The user sees a normal install finish and a Microsoft window, while the promised payroll app never appears; the result is remote control of a machine that can move money.
That makes the exposure sit at the workstation that initiates payroll, not at the payroll website itself. In a shop that uses web-only payroll or HR tools, a convincing desktop wrapper can be enough to hand an attacker the box that can divert or drain paychecks.