The Attack: Remote Access Disguised as Legitimate Software
Attackers created fake desktop applications impersonating three major US payroll platforms that have never released desktop software. The lure pages, built with an AI app builder and hosted on Vercel behind bot-challenge screens, offered downloads that appeared to be official payroll management tools.
The payload was a 64MB NSIS installer that executed in two stages. First, it ran the legitimate Microsoft-signed .NET Desktop Runtime 8.0 installer, which displayed normal progress windows and a success message. Then it used msiexec with the /qn flag to silently install ScreenConnect in the background with no user interface. The only visible prompt was a standard Windows elevation dialog between the two stages.
The ScreenConnect client was configured for unattended access with all user notifications disabled — no “under control” banner, no tray icon, no connection notifications. It installed as a Windows service, ran in Safe Mode, created scheduled tasks, and loaded on the Windows sign-in screen to allow access before any user logged in.
The target was payroll administrators. Unattended access to their machines provides a direct path to diverting or draining an entire company’s payroll. The GitHub-hosted installers were downloaded 291 times before takedown.
Why It Worked: Legitimate Tools Used Maliciously
ScreenConnect is a legitimate remote access tool. The .NET runtime installer is signed by Microsoft. The NSIS installer framework is widely used for legitimate software. Nothing in this attack chain looks obviously malicious to signature-based detection — 32 of 70 security engines flagged it, meaning 38 didn’t.
The attack succeeds because it writes files to disk that the user didn’t actually authorize. The victim thought they were installing a payroll application. What actually landed was a remote access client configured to give an attacker persistent, invisible control.
The Kernel-Level Prevention
FileSure Defend operates at the Windows kernel filter driver layer, intercepting file operations before they reach the file system. A policy blocking unauthorized programs from writing executable files to system directories would have stopped this attack at the delivery stage.
Here’s the specific rule configuration that applies:
File name filter: *.exe, *.dll, *.sys
Program name filter: DENY: msiexec.exe (when launched with /qn flag), NSIS installers not on authorized list
Operations: WRITE, CREATE
Target paths: C:\Program Files\*, C:\Windows\System32\*, %APPDATA%\ScreenConnect\*
When the NSIS installer attempts to write the ScreenConnect executable, FileSure intercepts the write operation at the kernel level and blocks it. The installer runs, but the payload never lands on disk. No ScreenConnect client means no remote access, no persistent service, no scheduled tasks, and no payroll theft.
The user sees the legitimate Microsoft .NET installer complete successfully. Then nothing happens — because the malicious payload was blocked before it could write to the file system. The attack stops at delivery, before the attacker ever gets access.
This is upstream intervention. The article describes what happens after the attacker gains access — persistent control, scheduled tasks, pre-login access. FileSure prevents the “after” by controlling the file operations that make the “during” possible.
Try It Yourself
FileSure Defend runs on all Windows versions, integrates with existing RMM tools, and ships with pre-configured rules for common threats. Install it, try to run a suspicious installer, and watch the write operation get blocked in real time.
Start your free 21-day trial at bystorm.com — 1 server, 10 workstations, full functionality, no credit card required.
Source: Fake payroll desktop apps hand attackers a route to company paychecks – Help Net Security
Category: Threat Intelligence
Tags: screenconnect, remote access trojan, payroll security, nsis installer, kernel filter driver, file write blocking, executable payload delivery