Attackers Distributed Fake Payroll Apps to Gain Access

A campaign targeting U.S. payroll systems utilized AI-built landing pages to install silent remote access tools.

Updated on Sept. 25, 2026 in Cybersecurity

Attackers Distributed Fake Payroll Apps to Gain Access

Live Poll

Do you feel confident verifying that the desktop applications you use for work are legitimate?

Attackers have deployed malicious desktop applications masquerading as legitimate U.S. payroll and HR tools to establish persistent, unattended remote access. Security firm Allure Security has since disabled the associated lure pages and the command-and-control infrastructure used in the campaign.

Why it matters

This campaign demonstrates how attackers leverage rapid AI-based page builders and hosted platforms to target enterprise workstations. The primary goal was gaining unauthorized access to company computers to divert or drain corporate payroll funds.

The 64 MB installer files were flagged as malicious by 32 of 70 security engines. The malware communicated with a command-and-control server at 89.213.118.127 on port 8041.

The players

Allure Security

A cybersecurity firm that specializes in identifying and mitigating digital deception and credential theft campaigns.

Lovable

An AI-powered web development platform used in this instance to rapidly generate deceptive landing pages.

Vercel

A cloud platform provider whose bot-challenge security features were exploited to shield malicious infrastructure.

The details

The attackers used the AI builder Lovable to create convincing lure pages, which were hosted behind Vercel's bot-challenge screen to prevent detection. The installer executes a genuine Microsoft .NET Desktop Runtime before silently installing ScreenConnect, a legitimate remote-support application. By configuring ScreenConnect for unattended access, the operator ensured persistent control over the infected machine.

Timeline

  1. July 24, 2026: SSL.com revoked a certificate used for early malware samples.

  2. August 2026: The command-and-control server and payload remained active.

  3. September 2026: Branded lure pages surfaced online.

  4. September 25, 2026: The security findings were published.

The Tech Race

This campaign follows the trend of using automated AI tools to decrease the cost and effort required to produce high-fidelity phishing lures. It reflects a broader race between threat actors using generative AI for scale and security firms employing automated detection to shutter infrastructure.

Users should verify that payroll and HR software is downloaded exclusively from official corporate portals or verified vendor domains. If an installer file appears unexpectedly or originates from a third-party hosting site like GitHub, it should be treated as unauthorized.

The takeaway

The effectiveness of this campaign relied on masking malicious behavior behind legitimate infrastructure like Vercel and ScreenConnect. Security teams should monitor for unusual unattended remote access configurations on employee workstations that handle financial data.

Further reading

For more on evolving threat landscapes, visit Cybersecurity.

Source note: This article includes information reported by Help Net Security.

Live Poll

Do you feel confident verifying that the desktop applications you use for work are legitimate?

Attackers Distributed Fake Payroll Apps to Gain Access