An unidentified threat operator impersonated three U.S. payroll and HR providers with fraudulent desktop-app download pages, despite the legitimate services being browser-only. The installers showed a legitimate Microsoft-signed .NET Desktop Runtime installation as decoy activity while silently deploying a customized ScreenConnect remote-access client, giving the attacker unattended control of Windows systems used by payroll personnel.
The operation used Lovable-generated phishing pages hosted on Vercel behind bot challenges and GitHub repositories distributing brand-specific NSIS installers. The implanted ScreenConnect clients connected to an attacker-controlled server at jyleatyg[.]com over port 8041, exposing victims to payroll-account takeover, payment diversion, and theft; Allure Security linked the lures to one operator and reported the pages, GitHub profile, and command-and-control domain were taken down.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Samples from September were unsigned, unlike earlier installers that used the subsequently revoked SSL.com certificate.
The attacker-controlled ScreenConnect server at jyleatyg[.]com and an operational payload were active, preceding the appearance of the branded payroll lure pages.
SSL.com revoked a certificate issued to Dennis Miller that had been used to sign earlier malicious installers. The revocation occurred on the certificate's stated issuance date.
Allure Security reported that the fraudulent payroll pages, the ScreenConnect C2 domain, and the GitHub profile distributing the installers were taken down.
An unidentified operator impersonated three U.S. payroll and HR platforms with Vercel-hosted lure pages and GitHub-hosted NSIS installers. The installers used a legitimate .NET Runtime installer as a decoy before silently installing an unattended ScreenConnect client connected to the actor's server.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.