Allure Security has documented a campaign impersonating three large US payroll and HR platforms with "native desktop apps" that none of them offers — all three ship browser-based products with mobile companions. The fake pages were built with the AI app builder Lovable, saved as single HTML files and hosted on Vercel behind its bot-challenge screen, which is why automated scanners left almost no public footprint while they were live. The download served a roughly 64 MB NSIS installer from a GitHub release that runs the genuine Microsoft-signed .NET Desktop Runtime 8.0.26 installer to a success message, then invokes msiexec /qn in the background to install ConnectWise ScreenConnect as a Windows service — banner, tray icon and connection notifications disabled — that survives Safe Mode and loads at the sign-in screen. The victim population is whoever runs payroll, which the researcher frames as a path to draining an entire company's wage run. All three lure pages shared one LiveChat account, one GitHub account and one C2 server (jyleatyg[.]com, 89.213.118[.]127, port 8041, Germany), tying them to a single operator whose server and a working payload predate the branded pages by a month; the earlier installers were signed with a certificate issued to "Dennis Miller" and revoked on its issue date of 24 July, while September samples were unsigned. GitHub downloads totalled 291 including researchers, and 32 of 70 engines flagged the installer. A parallel cluster runs the same playbook against cryptocurrency brands.
| Attribute | Detail |
|---|---|
| Sector | Financial Services |
| Date | 2026-09-27 |
| Source | Allure Security |
| Reliability | Tier 1 |