Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Hackers use fake desktop apps to hide ScreenConnect access

Cybercriminals impersonated three major US human resources and payroll platforms with fake desktop app offers, according to research from Allure reported by TechRadar. The platforms were not identified.

The researchers said the attackers used Lovable, a legitimate AI-powered website-building service, to create landing pages that imitated the brands but offered desktop clients. The platforms are cloud-based services accessed through a browser, and the source says they do not have legitimate desktop clients.

People who clicked the download button received an executable through GitHub Releases. The executable was a variant of ConnectWise’s ScreenConnect, a legitimate remote access and IT support tool. Researchers said it was configured for unattended access, with indicators such as a control banner, system-tray icon and connection notification turned off. This could let attackers connect without the user being notified.

Allure did not identify the attackers or say whether the campaign succeeded. GitHub’s download page showed 291 downloads, but that figure does not establish how many victims or successful attacks there were; researchers and automated analysis systems may also have downloaded the file. The researchers said the campaign appeared aimed at finance and HR departments. Allure suggested the access could be used for payroll fraud, but did not establish the attackers’ goal or report any resulting losses.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.