Hackers build fake desktop apps to trick victims into handing over access

Cybersecurity researchers at Allure have uncovered a sophisticated phishing campaign targeting HR and payroll professionals. Attackers are using AI-powered tools to create convincing landing pages for non-existent desktop versions of popular cloud-based payroll platforms. Victims are lured into downloading a modified version of the legitimate ScreenConnect remote support software hosted on GitHub. Once installed, the application provides attackers with silent, unattended remote access to the victim's machine, bypassing standard security alerts. By targeting employees with access to financial systems, the threat actors aim to facilitate wire fraud and payroll diversion. While the campaign shows approximately 291 downloads, the actual number of compromised systems remains unclear. Security experts warn that because the malware utilizes legitimate software, it remains difficult for traditional antivirus solutions to detect, necessitating heightened vigilance among corporate finance and HR departments regarding unauthorized software installations.
This is a summary. Read the full article at the original source:
TechRadarRelated stories
A critical zero-day vulnerability has been discovered in the TDengine time-series database, a platform widely utilized across industrial, Internet of…
EncryptPro has launched a promotional offer for its Personal Plan, providing a lifetime subscription for Windows users at a discounted price of $39.99…
A new threat actor is leveraging the Carbonato botnet to compromise exposed Docker hosts, deploying the open-source Hermes Agent AI framework to facil…



