Hackers spoof US HR platforms with fake desktop apps built via AI
Unidentified threat actors have created counterfeit desktop applications for three major US HR and payroll platforms using an AI website builder to trick victims into granting remote access.

Fake clients mimic real services
Threat actors used the legitimate AI service Lovable to generate landing pages that imitated well-known brands. These pages offered a desktop client download, even though no such official software exists for these cloud-based platforms. Victims who downloaded the modified ScreenConnect build from GitHub gave attackers hidden and unattended remote access without realizing it.
Campaign targets payroll staff
The campaign recorded approximately 291 downloads of the malicious software according to new research from Allure. Attackers likely chose these specific targets because their services are accessed through browsers rather than standalone desktop applications. This lack of a reference point makes it very difficult for users to determine they were being targeted.
Reported by one outlet
Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.
Reported by
1 independent outlet. Headline as published. Links open the original report.