Attackers Distributed Fake Payroll Desktop Apps
Threat actors utilized deceptive payroll apps to install unauthorized remote access tools on corporate systems.
Updated on Sept. 25, 2026 in Cybersecurity

Live Poll
Do you feel confident verifying that the desktop applications you use for work are legitimate?
Hackers created fake payroll and HR platform desktop applications that surreptitiously installed ScreenConnect remote access software. The malicious installers were hosted on GitHub and designed to provide attackers with unattended access to systems.
Why it matters
The campaign targeted HR and payroll computers with the explicit goal of diverting or draining corporate funds. By compromising these specific workstations, attackers gain a direct pathway to sensitive financial infrastructure.
The 64 MB malicious installer utilized a genuine Microsoft .NET Desktop Runtime before deploying ScreenConnect. The command-and-control server operated on port 8041 at IP address 89.213.118.127.
The players
Allure Security
This cybersecurity firm provides data protection and threat detection solutions.
GitHub
This platform provides software development hosting services used for collaborative coding.
Vercel
This cloud platform offers tools for deploying and scaling web applications.
ScreenConnect
This software provides remote support and access capabilities for IT professionals.
The details
The attackers used AI-generated lure pages hosted behind Vercel bot-protection screens to distribute the software. Allure Security identified the single operator behind the campaign and successfully removed the lure pages and command-and-control infrastructure.
Timeline
July 24, 2026: SSL.com revoked the certificate for early samples.
August 2026: The command server and payload were active.
September 2026: Branded lure pages appeared.
September 25, 2026: Article publication date.
The Tech Race
This campaign highlights the ongoing arms race where attackers repurpose legitimate tools like ScreenConnect to evade detection. The industry has seen a shift toward using AI-generated assets to scale the deployment of these deceptive vectors against legacy enterprise systems.
Users should verify the authenticity of any payroll or HR software installers by checking official vendor websites rather than GitHub repositories. Implementing strict application whitelisting and monitoring for unauthorized remote access tools can help mitigate these risks.
The takeaway
Maintaining caution when downloading desktop applications is essential even when branding appears legitimate. Organizations should prioritize multi-factor authentication and endpoint monitoring to prevent attackers from establishing persistent, unattended access.
Further reading
For more information on current digital threats, see the Cybersecurity section.
Source note: This article includes information reported by Help Net Security.
Live Poll
Do you feel confident verifying that the desktop applications you use for work are legitimate?






