Security researchers at Allure Security have uncovered a campaign that tricks payroll administrators into installing fake desktop apps for three major US payroll and HR platforms. None of these platforms actually offers a desktop application, but the lure pages looked convincing, complete with logos, screenshots, and a download button. The pages were built using the AI app builder Lovable and hosted on Vercel behind a bot-challenge screen, which helped them evade automated scanners.

When a victim runs the installer, it first shows a genuine Microsoft-signed .NET runtime installer that completes normally. Then, in the background, it silently installs ScreenConnect, a legitimate remote access tool, configured for unattended access with all notifications disabled. The attacker can then control the machine before the user even logs in, giving them a direct path to company payroll systems. The researchers noted that the only visible window is Microsoft's, so nothing appears suspicious.

All three lure pages used the same live-chat account, GitHub account, and command-and-control server, indicating a single operator. The payloads connected to a server in Germany, and the installers were downloaded 291 times. While that number is modest, the potential impact—draining an entire company's payroll—makes the threat significant. The researchers also found similar fake apps for cryptocurrency brands, but attributed those to a separate operator.

Allure Security has since taken down the fake payroll pages, the command-and-control domain, and the GitHub repositories hosting the installers. They advise companies using cloud payroll or HR platforms to verify whether the vendor actually offers a desktop app and to warn employees that any such download is not an upgrade—it's the attack.