Hackers create fake desktop apps to trick victims into giving up access


  • Threat actors spoofed major US HR and payroll platforms with fake desktop clients created through Lovable landing pages.
  • Victims downloaded a modified ScreenConnect build from GitHub, giving attackers hidden, unattended remote access
  • The campaign shows ~291 downloads; likely targets payroll staff, allowing for potential wire fraud through rerouted payments

Cybercriminals are impersonating large American human resources and payroll platforms in attacks that are very difficult to detect, new research from Allure claims.

Their report revealed how as-yet-unidentified threat actors were found to be spoofing three major US payroll and HR platforms, likely chosen primarily because they offered a cloud-based service accessible through a browser, rather than a standalone desktop application.

Avatar photo

Miraj Islam is a writer and contributor at Oalanbrado, interested in news, current events, technology, lifestyle, and stories that matter to readers. He enjoys researching different topics and turning information into clear, useful, and engaging articles. Through his work, Miraj aims to keep readers informed with fresh perspectives and easy-to-understand content from Brazil and around the world.

Post Comment