Hackers Can Use MedusaHVNC to Control Your PC on a Desktop You Cannot See
ID: 9aee5355-6e71-5f75-b06a-43ec891dbc04
STIX ID: report--9aee5355-6e71-5f75-b06a-43ec891dbc04
Feed Name: cybersecurityNews.com
MedusaHVNC is a stealthy hidden-VNC (HVNC) remote-access Trojan offered via malware-as-a-service that creates a separate, invisible Windows desktop on an infected machine so attackers can operate the victim's real browser (with cookies, sessions, and saved logins) to bypass device- and location-based fraud detection. The report details a multi-stage infection using an obfuscated JScript launcher, AutoIt unpacking, living-off-the-land injection into charmap.exe, layered XOR/ChaCha20 decryption, raw-TCP C2 communications, and native Windows APIs for screen capture, synthetic input, and clipboard theft, and advises monitoring for unusual charmap.exe child processes, AutoIt execution, suspicious Startup entries, and outbound connections to uncommon high ports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
