Hackers create fake desktop apps to trick victims into giving up access
- Threat actors spoofed major US HR and payroll platforms with fake desktop clients created through Lovable landing pages.
- Victims downloaded a modified ScreenConnect build from GitHub, giving attackers hidden, unattended remote access
- The campaign shows ~291 downloads; likely targets payroll staff, allowing for potential wire fraud through rerouted payments
Cybercriminals are impersonating large American human resources and payroll platforms in attacks that are very difficult to detect, new research from Allure claims.
Their report revealed how as-yet-unidentified threat actors were found to be spoofing three major US payroll and HR platforms, likely chosen primarily because they offered a cloud-based service accessible through a browser, rather than a standalone desktop application.
The criminals used Lovable (a legitimate AI-powered service for creating websites and landing pages with nothing more than prompts, requiring no technical knowledge) to create landing pages that mimicked legitimate brands, but with one small (but important) distinction: they offered a desktop client.
Latest videos ofTechnologyRadar
No reference points
Since there is no legitimate desktop client, there is nothing to compare the malware to. This, says Allure, makes it very difficult for victims to determine that they were being attacked. After all, it would make sense for a major HR and payroll platform to have a desktop app at some point, right?
Those who clicked the download button received a GitHub Releases executable, a GitHub feature that developers use to publish specific packaged versions of their software. You can think of it as the software equivalent of a product download page. Being a legitimate service (and one that is frequently used to host software like this), it has yet to raise any suspicions or red flags.
The executable itself is also not malicious, which is probably the most brazen part of the attack. As such, it goes undetected by most antivirus or endpoint protection services and can be easily installed on the device.
Well, if it’s not malicious, what is? And what is the risk?
The program that victims end up installing is a ScreenConnect variant of ConnectWise, a remote desktop and remote IT support platform used primarily by IT departments and managed service providers (MSPs). It is a legitimate tool that allows IT technicians to remotely connect to computers and servers, troubleshoot, install software and patches, and more.
But because ScreenConnect provides remote, often privileged, access to computers, it is an attractive tool for attackers and is often used in cyberattacks of a different nature.
“This build was configured to surreptitiously do the same thing without the user realizing. We extracted the client configuration and startup parameters. The access mode is set to unattended. The victim-facing indicators are disabled: there are no ‘your machine is being monitored’ banners, no systray icon, and no connection balloon,” the researchers said.
In other words, the variant was configured to allow criminals access without notifying the victim in any way.
Allure did not identify the attackers or discuss the success of the campaign. We don’t know exactly who it targeted (other than it targets finance and human resources departments), or how many organizations ended up installing ScreenConnect. The researchers said the GitHub downloads page shows 291 downloads, but that doesn’t necessarily mean 291 victims or successful attacks. It is likely that numerous security researchers downloaded the tools as well as the test environments, and many of the victims realized they had been attacked before suffering any significant damage. Therefore, the actual number of victims is likely to be significantly lower.
We also don’t know what the ending is, although Allure suggests it could be a wire fraud:
“The person who installs it is the person who manages the payroll, and unattended access to that machine is a way to divert or deplete a company’s entire payroll,” they said.
“If your company uses a cloud-based HR or payroll platform, the most useful thing you can do this week is to check if yours actually offers one. [desktop client]and telling employees that a download that the vendor does not offer is not an upgrade.”
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment