Impersonated HR Apps Pose Major Security Risk
HR and payroll staff face a dangerous new threat using fake desktop applications to steal remote access credentials. Learn how to protect your organization.
Fake HR apps
How Cybercriminals Target HR Departments With Spoofed Desktop Apps
Your HR team probably spends hours juggling employee records, benefits information, and payroll systems through web browsers. When a faster desktop version of familiar HR software appears online, the temptation to download it feels natural. That instinct, however, can hand attackers the keys to your entire network.
Allure Security discovered a sophisticated campaign impersonating three unnamed US-based HR and payroll platforms by offering desktop clients that don’t actually exist. The vendors behind these platforms have never released Windows applications—a crucial detail that should have raised red flags but likely didn’t for busy HR clerks.
What makes this attack so dangerous isn’t obvious malware or sketchy file hosting. Instead, cybercriminals built websites using Lovable, a legitimate AI app builder, and hosted the malicious installers on GitHub Releases—both trusted domains that bypass typical security scrutiny.
The Installation Trick: Hidden Remote Access Software
When someone downloads and runs the fake installer, they see what appears to be a standard Microsoft installer dialog. The software claims to install Microsoft .NET Desktop Runtime 8.0.26, so the entire installation process completes normally and shows a success message. Nothing seems amiss—until nothing happens next.
The real malice occurs silently in the background. The installer simultaneously deploys ConnectWise’s ScreenConnect remote access software without any visible indication to the user. ScreenConnect is legitimate monitoring and management software, which is precisely why this attack works so effectively.
What distinguishes this approach from typical malware attacks is that nothing in the chain technically violates security policies or uses inherently malicious code. The AI builder is legitimate. GitHub is trusted. Microsoft’s installer is genuine. ScreenConnect performs exactly as designed—just in the wrong hands.
Persistent Access With No Warning Signs
Once installed, the ScreenConnect client operates with unattended access mode enabled, meaning the attacker maintains control even when nobody is actively using the workstation. Allure Security emphasized that the installation deliberately disables all victim-facing indicators.
The compromised system won’t display the typical “your machine is being controlled” banner that normally appears during remote sessions. There’s no system tray icon, no connection balloon, and no obvious clues that someone else has access. The ScreenConnect client launches automatically on every boot and persists across different user sessions, establishing what researchers call “a quiet, persistent, interactive foothold.”
For an attacker with access to an HR workstation, the damage potential is catastrophic. Employee personal information, social security numbers, salary data, benefits selections, tax forms, and banking details all become accessible. This data can fuel identity theft, targeted phishing campaigns, or corporate espionage.
Why Detection Remains Difficult
Traditional security defenses struggle with this attack because it violates no common malware signatures. Standard antivirus tools recognize ScreenConnect as legitimate software and allow it to run. The Vercel hosting platform’s bot challenge page prevents search engines from indexing the phishing website, keeping it hidden from automated threat intelligence systems.
GitHub’s trusted reputation means security teams rarely scrutinize downloads from its platform. The entire infection chain appears clean to most endpoint protection solutions—until an attacker begins extracting sensitive data or pivoting deeper into the network.
Allure Security noted that the campaign’s infection method involves downloading files from a GitHub Releases page, which points to a domain that legitimate software developers use daily. This legitimacy becomes the perfect disguise.
What HR Teams Should Do Immediately
The first step requires direct communication with your HR and payroll software vendors. Contact each vendor’s support team and confirm whether they offer any desktop applications. If they don’t—and in this campaign, none of them do—alert every member of your HR and payroll departments immediately.
Create a simple list of authorized ways to access your HR systems. Include only the official web portal URLs and any legitimate desktop applications your vendors actually provide. Distribute this list to staff and make clear that any other download claiming to be from these vendors is a phishing attempt.
For IT teams, investigate whether anyone has downloaded suspicious installers claiming to be HR software. Allure Security reported that across the three fake applications, the GitHub download counts totaled 291 as of their report. While some of these downloads came from security researchers and sandboxes testing the threat, any legitimate employee downloads represent potential compromises.
Check for suspicious ScreenConnect processes running on HR department workstations. Look for the ScreenConnect client in your system processes and verify whether it was installed through official channels. Any unexpected instance should trigger immediate isolation of that machine and comprehensive forensic analysis.
Broader Implications for Remote Access Security
This campaign reflects a troubling trend in which attackers abuse legitimate remote monitoring tools rather than creating custom malware. Security researcher findings have documented multiple campaigns misusing ScreenConnect and similar RMM software as attack infrastructure.
The reason is simple: legitimate remote access tools bypass many security layers because they’re designed to work exactly like this—silently accessing systems without user interruption. Once installed through social engineering rather than malicious code, they become invisible to most defenses.
Organizations should establish policies requiring explicit approval before installing any remote access software, even from vendors. Implement application whitelisting where feasible to restrict which programs can run in sensitive departments like HR and finance.
FAQ: Protecting Your HR Systems
How can I tell if my HR software vendor actually offers a desktop app?
Check the vendor’s official website directly—not through a link from a suspicious email or website. Call their support line using the number listed on their main website. Legitimate vendors will confirm whether desktop applications exist and provide download links only from their official channels.
What should I do if someone in my HR department already downloaded the fake app?
Immediately disconnect that computer from the network and report it to your IT security team. Treat it as a potential breach and assume sensitive HR data may have been exposed. Professional incident responders should analyze the system to determine what information was accessed and for how long the attacker maintained access.
Can legitimate security tools prevent this type of attack?
Preventing the initial download requires user awareness training combined with email security and web filtering to block phishing pages. However, once users understand that their vendors don’t offer desktop applications, they become far less likely to fall for the scam.
Start your security review today by confirming with each HR and payroll vendor whether desktop applications actually exist. This single step prevents the attack’s entire infection chain from succeeding.



