New research exposes a sophisticated phishing tactic targeting finance and HR departments by tricking them into installing legitimate remote access software disguised as desktop clients for popular cloud payroll platforms.
- Fake desktop apps mimic popular US HR and payroll platforms to lure victims.
- Installed remote access software operates covertly without user alerts.
- Potential risks include unauthorized payroll changes and wire fraud.
What happened
Cybercriminals created convincing fake desktop applications for three major US HR and payroll platforms which traditionally offer only cloud-based browser access. These counterfeit apps were designed and distributed using Lovable, an AI website building service, to produce phishing landing pages that included an option to download a desktop client that does not exist in reality.
Victims who downloaded the software received a legitimate program hosted on GitHub Releases—a common and trusted platform for software distribution. This program was a modified variant of ConnectWise’s ScreenConnect, a remote desktop support tool, configured for stealth operation that disables user notifications, system tray icons, or connection banners, thereby enabling attackers to gain remote control without the victim’s knowledge.
Why it matters
This tactic exploits the trust users place in well-known cloud platforms and legitimate software hosting services. The absence of an official desktop client from the HR/payroll vendors makes the fake apps appear plausible, increasing the risk of employees installing unauthorized software.
Once installed, the stealthy remote access allows attackers to quietly take control over payroll or HR systems, presenting significant security risks such as unauthorized changes, data theft, or financial fraud. Because the remote access tool itself is legitimate software, it evades detection by many conventional antivirus and endpoint security solutions.
What to watch next
Organizations using cloud-based HR and payroll platforms should immediately verify whether their vendors offer any official desktop applications and communicate clearly with employees about never downloading software outside authorized channels. This verification is critical to prevent fallbacks to fake clients that enable remote attacker access.
Security teams and end users should also monitor GitHub Releases and similar trusted repositories for suspicious downloads impersonating legitimate software. Deploying enhanced endpoint detection strategies that monitor behavior rather than file signatures will be essential to catch these stealthy remote control tools moving forward.