Skip to content

Security1 publisher3 min readPublished

Attacker impersonates three payroll platforms to plant ScreenConnect on payroll PCs

A single operator is distributing fake "desktop apps" for three US payroll platforms that have no desktop product. Each installer silently sets up ScreenConnect for unattended control of the payroll operator's machine, Allure Security found.

The Watch · Security desk

Illustration accompanying Attacker impersonates three payroll platforms to plant ScreenConnect on payroll PCs

What happened

  • Allure Security found an attacker offering fake "desktop apps" for three large US payroll and HR platforms, all of which sell only browser and mobile products and have never shipped a desktop application.
  • Shared GitHub and LiveChat accounts and a single ScreenConnect server, jyleatyg[.]com on port 8041 in Germany, tie all three lures to one operator.
  • The GitHub installers were downloaded 291 times, a count that includes researchers and sandboxes, and 32 of 70 engines flagged the file as malicious at analysis time.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Whoever installs it is usually the payroll operator, so one silent takeover puts a company's entire pay run within the attacker's reach.
  • decision Because none of the three platforms ships a desktop application, payroll teams can be handed one flat rule: a "desktop app" for these vendors does not exist, so the download itself is the attack.
  • capability Loading at the sign-in screen and running in Safe Mode gives the operator access before login and across reboots, so this is durable control of the host.
  • precedent It is at least the third 2026 report of ScreenConnect delivered through lure apps, after Microsoft in March and Huntress in September; the AI-built tooling is cheap and repeatable.

The pages that carried these installers were built with Lovable, an AI app builder that turns a text prompt into a web page, and the operator left the build metadata in place. According to Allure Security, each page was created in Lovable, saved as a single HTML file with a browser extension called SavePage WE, and hosted on Vercel. Every page carried the impersonated brand's logo, product screenshots, a live-chat widget and a download button [6][7][8].

The pages sat behind Vercel's bot-challenge screen. "Automated scanners hit the challenge page and stopped, without accessing the lure, which is why the pages left almost no public scanning footprint while they were live," Ryan Merritt, Allure's Director of Security Research, said [9].

The download button pointed to a release file in a GitHub repository. One account held a separate repository for each brand, and each published the same 64 MB NSIS installer under a brand-specific name [10][11]. When it runs, it opens the genuine, Microsoft-signed .NET Desktop Runtime 8.0.26 installer first, then calls msiexec with the /qn flag to install ScreenConnect in the background with no window; a standard Windows elevation prompt sits between the two steps [12]. "So the only thing the victim sees is a real Microsoft installer finishing normally. The promised payroll app never opens, because it does not exist, and the one window that did appear belonged to Microsoft. Nothing on screen looks like malware," Merritt wrote [13].

The installed client is set for unattended access, with the "under control" banner, tray icon and connection notifications turned off. It runs as a Windows service, works in Safe Mode, creates scheduled tasks and loads at the Windows sign-in screen, so the operator can reach the machine before anyone logs in [14].

The infrastructure predates the branded pages. The server and a working payload were in use in August, a month before the pages appeared [17]. Those August installers were signed with a certificate issued to "Dennis Miller" by SSL.com, which revoked it on July 24, 2026, the day it was issued; the September samples were unsigned [18].

Reach was small, on the operator's own account. "On reach, the numbers are modest, but when you consider the potential impact of drained company payroll accounts, they are non-trivial," Merritt said [21]. How victims reached the pages, through ads, search results or email, has not been established [22].

The payload is legitimate software. ScreenConnect is a genuine remote-access product, so installing it does not look like an attack, and fewer than half the engines that saw the file called it malicious [5][20]. A better check does not rely on scanners at all. None of the three platforms ships a desktop application, so any "desktop app" branded to them is fake before it runs [2].

Two other 2026 reports describe the same move. Microsoft reported in March on a campaign impersonating workplace apps including Teams, Zoom and Adobe Reader to deploy ScreenConnect and other remote-access tools [23], and Huntress reported in September on rogue ScreenConnect clients spread through tech-support lures [24]. Allure also found fake desktop apps for cryptocurrency exchange, wallet and DeFi brands built with the same tooling and the same kind of ScreenConnect payload, which it attributes to a separate operator [25].

What to watch

  • Whether Allure or the payroll vendors name the three impersonated platforms, which would let staff be warned by brand.
  • Whether takedowns of the Vercel pages, the GitHub repositories and the jyleatyg[.]com server hold, or the operator rebuilds with fresh Lovable pages.
  • Whether the crypto-brand fake apps built with the same tooling share infrastructure with this operator or are genuinely distinct.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories