Skip to content
Fake Desktop Apps Exploit HR Staff for Remote Access

Fake Desktop Apps Exploit HR Staff for Remote Access

First seen 27 Sep 2026, 00:20 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 22:57 UTC
  • •Attackers impersonate HR software to gain remote access.
  • •Over 25 organizations, including a Fortune 500 company, are affected.
  • •Malicious downloads are hosted on trusted platforms like GitHub.

A recent cyber campaign has targeted HR departments of multiple organizations, including a Fortune 500 hospitality company and a major US airline, by using fake desktop applications. These apps impersonate legitimate HR and payroll software, tricking employees into installing them. Once executed, the fake app installs ConnectWise's legitimate ScreenConnect software, granting attackers persistent remote access. The campaign exploits the lack of awareness among HR staff, as the impersonated providers do not actually offer desktop applications. The malicious downloads are hosted on a GitHub Releases page, adding to their credibility. Allure Security reported the discovery of this campaign, which has affected over 25 organizations. The exact targeting method remains unclear, but the threat is significant due to the sensitive data that could be exposed.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 19h ago How this analysis works

Timeline

2026-09-25
Fake desktop apps discovered
Allure Security reported a campaign using fake HR software to install remote access tools on victims' PCs.
Theregister
2026-09-26
Campaign reported to target multiple organizations
The campaign has reportedly affected a Fortune 500 hospitality company, a major US airline, and over 25 other organizations.
Theregister

More articles in this cluster (5)

Following this threat?

Track FBI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed