A cybersecurity firm is urging payroll and HR professionals to be cautious following the discovery of a new threat which has seen threat actors using fake desktop apps to gain remote access to company data, The Register reports.
According to Allure Security - the firm that reported the discovery of the threat - this is the latest evolution of a trend that has abused ScreenConnect and other remote monitoring and management software.
A downloadable Windows version of recognisable HR software appears, offering a faster alternative to the usual web interface. Once clicked, the link silently installs ConnectWise's legitimate ScreenConnect software, giving the operator persistent remote access to the affected PC.
The tell of this fraud is reportedly that none of the purported vendors offers the Windows app being advertised.
Allure stated that the scam impersonates three unnamed US-based HR and payroll platforms, offering fake desktop clients for those providers’ software. In all three cases, those companies don’t offer a desktop client. However, HR or payroll professionals unaware of this could be lured by promises of superior performance to expose sensitive data.
Allure has yet to identify how potential victims are being targeted but warns that those who have been exposed may not be aware that anything is wrong.
Clicking through to the website offering the fake app reportedly brings up a legitimate-looking site built using AI app builder Lovable and hosted on Vercel. The site is hidden behind the cloud host’s bot challenge page; thus, scrapers haven’t been able to index it and expose the scam.
In addition, the downloads are hosted on a GitHub Releases page, so they point to a trusted domain.
Once downloaded and executed, Allure says the installer presents the victim with an actual Microsoft installer to make it appear like a legitimate piece of software. It actually installs the Microsoft .NET Desktop Runtime 8.0.26, going through the entire process and showing that an installation completes, yet nothing pops up, leaving the target unsure where their desktop app went.
But behind the scenes, the installer runs a quiet, no-interface installer to drop the ScreenConnect client on the victim’s machine.
“The [ScreenConnect] access mode is set to unattended,” Allure Security said. “The victim-facing indicators are turned off: no ‘your machine is being controlled’ banner, no system-tray icon, no connection balloon.”
It added, “Nothing in this chain is malware in the usual sense. The page was generated by a legitimate AI builder and served by a legitimate host. The download came from a legitimate code platform. The one window the victim saw belonged to Microsoft. The thing that was installed is a legitimate RMM product, doing what it was designed to do, for someone who was never supposed to have it.”
Anyone with concerns is urged to check with HR and payroll vendors to see whether they offer a desktop app, and to alert all members of those teams to this campaign if the answer is no.
Source: The Register
(Links and quotes via original reporting)
A cybersecurity firm is urging payroll and HR professionals to be cautious following the discovery of a new threat which has seen threat actors using fake desktop apps to gain remote access to company data, The Register reports.
According to Allure Security - the firm that reported the discovery of the threat - this is the latest evolution of a trend that has abused ScreenConnect and other remote monitoring and management software.
A downloadable Windows version of recognisable HR software appears, offering a faster alternative to the usual web interface. Once clicked, the link silently installs ConnectWise's legitimate ScreenConnect software, giving the operator persistent remote access to the affected PC.
The tell of this fraud is reportedly that none of the purported vendors offers the Windows app being advertised.
Allure stated that the scam impersonates three unnamed US-based HR and payroll platforms, offering fake desktop clients for those providers’ software. In all three cases, those companies don’t offer a desktop client. However, HR or payroll professionals unaware of this could be lured by promises of superior performance to expose sensitive data.
Allure has yet to identify how potential victims are being targeted but warns that those who have been exposed may not be aware that anything is wrong.
Clicking through to the website offering the fake app reportedly brings up a legitimate-looking site built using AI app builder Lovable and hosted on Vercel. The site is hidden behind the cloud host’s bot challenge page; thus, scrapers haven’t been able to index it and expose the scam.
In addition, the downloads are hosted on a GitHub Releases page, so they point to a trusted domain.
Once downloaded and executed, Allure says the installer presents the victim with an actual Microsoft installer to make it appear like a legitimate piece of software. It actually installs the Microsoft .NET Desktop Runtime 8.0.26, going through the entire process and showing that an installation completes, yet nothing pops up, leaving the target unsure where their desktop app went.
But behind the scenes, the installer runs a quiet, no-interface installer to drop the ScreenConnect client on the victim’s machine.
“The [ScreenConnect] access mode is set to unattended,” Allure Security said. “The victim-facing indicators are turned off: no ‘your machine is being controlled’ banner, no system-tray icon, no connection balloon.”
It added, “Nothing in this chain is malware in the usual sense. The page was generated by a legitimate AI builder and served by a legitimate host. The download came from a legitimate code platform. The one window the victim saw belonged to Microsoft. The thing that was installed is a legitimate RMM product, doing what it was designed to do, for someone who was never supposed to have it.”
Anyone with concerns is urged to check with HR and payroll vendors to see whether they offer a desktop app, and to alert all members of those teams to this campaign if the answer is no.
Source: The Register
(Links and quotes via original reporting)