Threats · 2h ago
Allure Security found fake desktop installers for three US payroll and HR platforms that never offered one, and the files dropped ScreenConnect on the victim machine. The lure is aimed at the people who actually run payroll, because control of that workstation can become control over the pay run.
The installer first shows a real Microsoft-signed .NET Desktop Runtime setup, then quietly launches ScreenConnect in the background with unattended access turned on. The user sees a normal install finish and a Microsoft window, while the promised payroll app never appears; the result is remote control of a machine that can move money.
That makes the exposure sit at the workstation that initiates payroll, not at the payroll website itself. In a shop that uses web-only payroll or HR tools, a convincing desktop wrapper can be enough to hand an attacker the box that can divert or drain paychecks.
2 sources covering this story
Crooks use fake desktop apps to fool HR staff into giving them remote access
Nothing in the attack chain screams malicious software, except none of the impersonated HR and payroll providers actually offers a desktop app
Fake payroll desktop apps hand attackers a route to company paychecks - Help Net Security
Fake desktop apps for US payroll platforms install hidden ScreenConnect, giving attackers control of the PCs that run company payroll.
Part of the PlainSec briefing for 2026-09-25