The payroll app that never existed: a lesson in checking the obvious
Researchers at Allure Security, reported by The Register and Help Net Security on 25 September 2026, documented a campaign impersonating three US-based HR and payroll platforms by offering fake desktop clients. Running the installer silently deployed ConnectWise ScreenConnect — entirely legitimate remote access software — configured to hand the operator persistent control of the machine. The people most likely to install it are the people who run payroll.
How it worked
The attackers built download pages for desktop versions of three HR and payroll platforms. The pages were constructed with the AI app builder Lovable and hosted on Vercel, sitting behind the host's bot challenge page so that scrapers could not index them and surface the scam. The installers themselves were served from a GitHub Releases page.
Anyone who ran one received a working copy of ScreenConnect, pre-configured for the attacker, with no indication that anything unusual had happened. Allure Security has since had the three fake pages, the command-and-control domain and the GitHub profile taken down. Download counts across the three fake installers totalled 291 at the time of the report.
- The giveaway
- None of the three impersonated vendors offers a desktop client at all.
- The payload
- Legitimate remote access software, which is why it does not look like malware.
- The target
- Payroll and HR staff — unattended access to their machine is a route to an entire company's payroll.
Three things worth taking from this
1. "Does this product even exist?" is a real control. The whole campaign rests on a premise nobody checked. A staff member wanting a desktop app searched for one, found a professional-looking page and installed it. A single habit — reach software from the vendor's own domain, reached from your records, not from a search result — defeats the entire scheme. That is a cheap thing to teach and it generalises well beyond payroll.
2. Legitimate tools are the payload of choice. ScreenConnect is used by thousands of IT teams for perfectly good reasons, which is exactly why attackers reach for it. It is signed, it is known, and it does not trip the tooling that looks for malware. If your organisation does not maintain a list of which remote access and monitoring tools are sanctioned, then every one of them looks equally plausible when it appears on an endpoint. That list is worth writing down, and worth alerting on when something outside it installs itself.
3. Convincing fakes now cost almost nothing. The pages were assembled with an AI app builder and hosted on mainstream infrastructure. The old advice to look for poor spelling and amateurish design has expired. Judgement has to move from how a page looks to where it came from.
Why payroll specifically
Payroll teams sit on an unusual combination: the authority to move money on a schedule, and some of the most sensitive personal data an organisation holds — bank details, national insurance numbers, salary, addresses, and often health-related absence records. Persistent access to a payroll clerk's workstation offers fraud and a serious personal data breach in the same compromise.
It also tends to be a function with its own software relationships, procured outside IT, supported directly by the vendor. That independence is usually sensible. It does mean the people making software decisions may not have an obvious route to ask "is this real?", which is a gap worth closing deliberately rather than assuming.
Practical steps
- Tell finance and HR which vendors offer what. A short list of your payroll platforms and how they are legitimately accessed — browser only, or a named app from a named domain.
- Inventory sanctioned remote access tools, and alert on the rest. Unexpected RMM software installing itself is one of the higher-value detections available.
- Restrict who can install software. Unremarkable advice, but this campaign needed a user with the rights to run an installer.
- Include payroll in supplier assurance. If it holds employee personal data, it belongs on the register with everything else, along with the question of how staff are meant to reach it.
Get every supplier holding employee data onto one register, and keep checking them.
Explore TPRMCommon questions
ConnectWise ScreenConnect, a legitimate remote access tool, configured so the attacker could control the machine without the user knowing. Because the software is genuine and signed, it does not look like malware to security tooling.
None of the three impersonated vendors offers a desktop client, so the product being downloaded did not exist. Reaching software from the vendor's own domain, via a record you already hold rather than a search result, defeats this class of attack entirely.
They combine authority to move money with access to highly sensitive personal data — bank details, national insurance numbers, salaries, addresses and often health-related absence records. Persistent access to a payroll workstation offers both financial fraud and a serious personal data breach.
Sources
- Crooks use fake desktop apps to fool HR staff into giving them remote access — The Register, 25 September 2026
- Fake payroll desktop apps hand attackers a route to company paychecks — Help Net Security, 25 September 2026