← Back to articles
Governance6 MIN READ

Fake HR Apps Are Stealing Payroll Access From SMBs

Hackers built AI-powered fake clones of US HR and payroll platforms to trick staff into downloading remote access tools. Here is how to spot and block it.

Alex Followell
Alex Followell
2026-09-29 · 6 min read
TL;DR

Threat actors are cloning major HR and payroll platforms with convincing fake desktop apps, then using them to install hidden remote access software on employee machines. This is not a phishing email you can train people to ignore; it is a fake app that looks identical to the real one. A recent campaign logged roughly 291 downloads of a weaponized ScreenConnect build hosted on GitHub, with payroll staff as the apparent target. If an attacker gets unattended remote access to a machine that touches payroll, the damage is immediate and hard to reverse.

Why are fake HR and payroll apps suddenly a serious SMB threat?

Because building a convincing fake app used to require real development skill. Now it does not. Attackers used AI-assisted tools like Lovable to spin up spoofed landing pages and fake desktop client downloads for major US HR and payroll platforms in days, not weeks. The barrier to entry collapsed, and small businesses are squarely in the crosshairs because they rarely have the security controls that enterprises do.

The campaign documented by Wilson's Media shows the full attack chain: a realistic spoofed site, a fake desktop app download, and a modified ScreenConnect binary hosted on GitHub that installs hidden, unattended remote access on the victim's machine. About 291 downloads were recorded before detection. That number sounds small until you realize each download likely represents a payroll or HR employee with direct access to banking details, direct deposit accounts, and employee records.

How does the attack actually work?

The attack has three steps, and each one is designed to look completely normal to a non-technical employee.

Step 1: The spoofed landing page. Attackers build a near-pixel-perfect clone of a real HR or payroll platform's marketing site using AI page builders. The domain is close enough to fool someone who is not looking hard. The page offers a "desktop client" download, which some legitimate platforms do offer.

Step 2: The fake app download. The download is a modified version of ScreenConnect, a legitimate remote desktop tool used by IT teams everywhere. Because ScreenConnect is a known, signed tool, it may not trigger antivirus alerts. The modification configures it to run silently and connect back to infrastructure the attacker controls.

Step 3: Unattended remote access. Once installed, the attacker can access the machine any time, without the employee knowing. They are not locked out when the employee closes a browser tab. They have persistent, quiet access to everything on that machine, including saved passwords, open payroll sessions, and connected bank accounts.

The goal is not to grab one paycheck. It is to sit quietly inside payroll systems long enough to redirect ACH transfers, exfiltrate employee PII, or pivot to other internal systems.

Who is actually being targeted here?

Payroll staff and HR coordinators. These are often non-technical employees who have more system access than almost anyone else in a small business. They process direct deposits, have admin credentials to HR platforms, and sometimes have view or edit access to company bank accounts.

In most SMBs, this person is not thinking about cybersecurity every time they download something. They are thinking about getting payroll out on time. Attackers know this. The social engineering is designed around urgency and legitimacy, two things that describe payroll work perfectly.

According to the 2024 Verizon Data Breach Investigations Report, 68% of breaches involve a human element, and credential theft and pretexting remain the top patterns. Fake app campaigns like this one are a direct evolution of those techniques.

What makes AI-generated fake apps harder to catch than phishing emails?

Traditional phishing awareness training teaches people to look for bad grammar, suspicious links in email, and mismatched sender addresses. That training does not help when the attack is a website and a download.

AI page builders like Lovable can produce landing pages that are visually indistinguishable from the real thing, including correct logos, real support copy pulled from the genuine site, and functional-looking navigation. The cognitive load on the employee is flipped: instead of spotting something wrong, they have to notice the absence of something they would never think to check.

And because the payload is a modified version of legitimate software, signature-based antivirus often misses it. This is not a novel malware binary. It is a known tool with its configuration changed.

How do you verify an app is legitimate before your team installs it?

The answer is process, not just awareness. Technical controls matter more than training alone here.

Verify download sources before anything gets installed:

  • Official vendor apps should only be downloaded directly from the vendor's authenticated website or a verified app store. Never from GitHub links on a third-party site.
  • Check the domain character by character. Attackers use lookalike domains with subtle substitutions (e.g., "paylocitv.com" instead of "paylocity.com").
  • Cross-reference the download with the vendor's official documentation. Call support if you are unsure.

Use an application allowlist on machines that touch payroll:

| Control | What It Does | Effort to Implement | |---|---|---| | Application allowlisting | Blocks any software not pre-approved from running | Medium: needs IT or MSP setup | | DNS filtering | Blocks known malicious domains before the page loads | Low: 30-minute setup with tools like Cloudflare Gateway | | Endpoint detection and response (EDR) | Catches behavioral anomalies like hidden remote access tools | Medium: requires agent deployment | | MFA on all HR/payroll platforms | Limits damage if credentials are stolen | Low: turn it on today | | Privileged access review | Limits who can touch payroll systems at all | Low: an afternoon of admin work |

Application allowlisting is the most direct counter to this specific attack. If ScreenConnect is not on your approved list, it cannot run, even if someone downloads and tries to install it.

What should you do if you think a machine is already compromised?

Do not just uninstall the suspicious app and move on. If ScreenConnect or any remote access tool was installed without IT authorization, assume the machine is compromised and treat it accordingly.

  1. Isolate the machine from the network immediately.
  2. Change credentials for every system that machine had access to, starting with payroll and banking.
  3. Alert your payroll and bank providers that a compromise may have occurred. They have fraud response protocols.
  4. Have a forensics-capable IT provider review the machine before it goes back into service.
  5. Check for ACH or direct deposit changes made in the last 30 days.

The window between compromise and payroll fraud can be very short. Speed matters.

What we'd actually do

  • Turn on DNS filtering today. Cloudflare Gateway has a free tier. It will block the spoofed domains used in campaigns like this before your staff can even reach the fake download page. This is a one-afternoon project.
  • Lock down who can install software on payroll and HR machines. Standard user accounts should not have local admin rights. If your payroll coordinator has admin rights on their laptop, that is the first thing to fix. Talk to your IT provider or MSP this week.
  • Build a one-page download verification checklist for anyone in HR or finance. It does not need to be long. It needs to cover: where to download software (vendor site only), who to call before installing anything new (internal contact), and what to do if something feels off (escalate, do not proceed). This checklist, combined with the technical controls above, closes most of the gap.

FAQ

How can I tell if a desktop app is a fake clone of a real HR platform?

Check the domain character by character against the vendor's official website, and download only from that verified site or an official app store. Never install software from a GitHub link shared on a third-party site. If anything feels off, call the vendor's support line directly before proceeding. One phone call is cheaper than a payroll breach.

Is ScreenConnect itself malicious?

No. ScreenConnect, now called ConnectWise ScreenConnect, is a legitimate remote desktop tool used by IT teams. In this campaign, attackers distributed a modified version configured to give them hidden, unattended access. The tool itself is not the problem; the unauthorized, covert installation is. If you did not have IT install it, it should not be there.

What is the fastest thing a small business can do right now to reduce this risk?

Enable DNS filtering on your network. Cloudflare Gateway offers a free tier and can be configured in under an hour. It blocks known malicious and spoofed domains before your employees can reach a fake download page. Then remove local admin rights from any machine that touches payroll or HR systems. Both steps require no new software budget.

JOIN THE COMMUNITY

Want this running in your business?

The Skool community is where we show the full builds, share the templates, and help you implement. Three tiers, from team training to fractional AI expert.

  • Weekly Q&A with Alex and Cameron
  • Templates and frameworks you can steal
  • Real builds, running in real businesses
Join skool.com/aiforbusiness ↗