Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Crooks Use Fake Desktop Apps to Fool HR Staff into Giving Them Remote Access


Crooks use fake desktop apps to fool HR staff into giving them remote access to their computers, tricking them into giving access to company data. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data. The attackers used fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

  • Attackers have been using fake desktop apps to trick HR staff into giving them remote access to company computers.
  • The attackers use fake desktop clients for three US-based HR and payroll platforms that do not offer desktop clients.
  • The attackers use promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.
  • The attackers use a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to gain access to victims' computers.
  • The attackers did not use any malicious software in the usual sense, but still managed to gain access to victims' computers.
  • The actual number of victims remains unknown, with 291 GitHub download counts as of the report.



  • Crooks have been using fake desktop apps to trick HR staff into giving them remote access to their computers. This is not a new tactic, but it has been seen to be particularly effective in recent months. According to cybersecurity outfit Allure Security, this is the latest evolution in a trend of abusing remote monitoring and management software.

    The attackers use fake desktop clients for three unnamed US-based HR and payroll platforms, which do not offer desktop clients in the first place. In all three cases, the companies do not provide desktop clients, and the attackers use promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    Once the victim clicks on the fake app, it presents them with a legitimate-looking site built using AI app builder Lovable and hosted on Vercel. The site is hidden behind the cloud host's bot challenge page, which prevents scrapers from indexing the scam. The downloads are hosted on a GitHub Releases page, which points to a trusted domain.

    The installer presents the victim with a Microsoft installer to make it appear like a legitimate piece of software. However, it actually installs the Microsoft .NET Desktop Runtime 8.0.26, which goes through the entire process of installation without any issues. Once the installation is complete, nothing pops up, leaving the victim unclear as to where their desktop app has gone.

    The installer also runs a quiet, no-interface installer to drop the ScreenConnect client on the victim's machine. The ScreenConnect access mode is set to unattended, and the victim-facing indicators are turned off, including no 'your machine is being controlled' banner, no system-tray icon, and no connection balloon.

    The silent install is also configured to launch on boot and stay connected across various user sessions, giving the attacker a quiet, persistent, interactive foothold. This means that the attackers have a steady and reliable way to access the victim's computer without being detected.

    Allure noted that the attackers did not use any malicious software in the usual sense. The page was generated by a legitimate AI builder, served by a legitimate host, and the download came from a legitimate code platform. The one window the victim saw belonged to Microsoft, and the thing that was installed was a legitimate RMM product doing what it was designed to do.

    The actual number of victims remains unknown, as Allure said that the GitHub download counts across the three fake downloads totaled 291 as of its report. Some of those came from Allure's researchers and possibly other researchers and sandboxes too, so the download count cannot be used to determine the actual number of victims.

    This latest campaign is a clear example of the evolving nature of cyber attacks. Attackers are becoming more sophisticated and using new tactics to trick victims into giving them access to their computers. It is essential for security teams to be vigilant and check with HR and payroll vendors to see if they offer desktop apps, and to alert all members of those teams to this campaign.

    In the age of AI, teaching networking principles remains more important than learning protocols. Kids can learn why BGP matters in a semester, but that won't leave them ready to implement it. The recent attack highlighted the importance of cybersecurity and the need for security teams to stay updated with the latest tactics and techniques used by attackers.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.

    The attackers used a combination of fake desktop apps, legitimate-looking sites, and quiet, no-interface installers to trick victims into giving them remote access to their computers. The attackers did not use any malicious software in the usual sense, but they still managed to gain access to the victims' computers.

    The attackers used a combination of social engineering and technical tactics to trick victims into giving them remote access to their computers. The attackers used promises of superior performance to trick unaware HR or payroll clerks into giving them remote access to company data.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Crooks-Use-Fake-Desktop-Apps-to-Fool-HR-Staff-into-Giving-Them-Remote-Access-ehn.shtml

  • https://www.theregister.com/security/2026/09/25/crooks-use-fake-desktop-apps-to-fool-hr-staff-into-giving-them-remote-access/5299226


  • Published: Fri Sep 25 14:01:03 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us