Fake Payroll Desktop Apps Deliver Unattended Remote‑Access Tool, Threatening Payroll Theft
What Happened — Attackers published fake “desktop apps” for three major U.S. payroll/HR platforms that do not offer native desktop clients. The installer silently deploys ScreenConnect, a legitimate remote‑access product, configured for unattended access.
Why It Matters for Trust & Control Assurance
- This scenario tests the effectiveness of your remote‑access governance: continuous monitoring, strict allow‑listing, and evidencing that only approved tools run on privileged workstations.
- It highlights the need for documented vendor‑software validation and audit‑ready evidence that any remote‑access connections are authorized and logged.
Who Is Affected – Payroll and HR technology providers, their enterprise customers, and any organization that processes employee compensation.
Recommended Actions – Verify software sources before installation, enforce application allow‑listing, monitor for unauthorized remote‑access services, and require MFA for any remote‑access sessions. Source: https://www.helpnetsecurity.com/2026/09/25/fake-payroll-desktop-apps-screenconnect/
Technical Notes – The malicious installer (NSIS, 64 MB) first runs a genuine Microsoft .NET Desktop Runtime 8.0.26 installer, then silently executes msiexec /qn to install ScreenConnect as a Windows service with disabled UI notifications. The lure pages were built with the AI app generator Lovable, hosted on Vercel, and the installer was distributed via GitHub repositories masquerading as brand‑specific files. Source: https://www.helpnetsecurity.com/2026/09/25/fake-payroll-desktop-apps-screenconnect/