CriticalSecurity & Privacy
Crooks use fake desktop apps to fool HR staff into giving them remote access
Attackers are impersonating HR and payroll software with fake desktop apps that install legitimate remote-management software, creating a stealthy, persistent foothold on employee endpoints and putting highly sensitive personnel and payroll data at risk. For CIOs, the key implication is that traditional malware defenses may miss abuse of trusted tools and infrastructure, so IT organizations need stronger vendor verification, endpoint control, and detection for unauthorized RMM deployments and silent installers. This campaign is a reminder that social engineering aimed at business functions can become an enterprise access problem, not just a fraud issue.
The Register2 min read