TechRadar News.
Technology

Fake HR Desktop Apps Deployed by Hackers to Secure Stealthy Remote Access

Fake HR Desktop Apps Deployed by Hackers to Secure Stealthy Remote Access

A team of security analysts has identified a fresh operation in which cyber‑actors circulate counterfeit desktop programs that pose as legitimate HR and payroll applications, with the goal of harvesting credentials and embedding covert remote‑access tools on corporate machines.

These deceptive bundles are delivered via slick “Lovable” landing pages that closely mimic the design of popular U.S. human‑resources and payroll services. Victims are persuaded to download what looks like an authentic client, yet the file is a compromised version of the ScreenConnect remote‑support utility, hosted on a public GitHub repo.

Review of the campaign’s infrastructure shows about 291 distinct downloads before the malicious repository was removed. The relatively low download volume points to a focused strategy, likely targeting payroll departments where access to employee payment information offers attackers a high monetary payoff.

Tools such as ScreenConnect are widely used by IT support staff because they let technicians view and control a user’s computer without being on site. By inserting hidden code into the installer, the perpetrators gain unattended access, allowing lateral movement within networks, theft of sensitive payroll data, and the possible deployment of ransomware.

Cyber‑security companies advise firms to confirm the provenance of any HR‑related software prior to installation, enforce strict code‑signing controls, and watch for abnormal outbound traffic that could signal a concealed remote‑access session. Users should also flag any unexpected prompts to download desktop clients, especially those originating from unofficial URLs or community repositories.

Law‑enforcement officials are said to be probing the individuals behind the scheme, and analysts warn that comparable methods may resurface as attackers continue to leverage trust in critical business applications. Maintaining vigilant monitoring and strong endpoint protection remains essential to counter this evolving threat.

Source: TechRadar
TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related