logo

MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data

ID: d3a2066d-fe5a-53eb-a0e4-38edcdee26fa

STIX ID: report--d3a2066d-fe5a-53eb-a0e4-38edcdee26fa

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Pierluigi Paganini

...
...

MedusaHVNC is a malware-as-a-service remote access trojan that abuses legitimate Windows hidden desktop functionality to launch real browsers out of view and hijack live sessions (cookies, passwords, history). The report details an infection chain (obfuscated JScript launcher → AutoIt decryption → loader injected into charmap.exe → ChaCha20-unpacked payload), in-memory execution with AMSI/ETW bypasses, HVNC capture/input techniques, baked-in C2 (51.89.204.28:4444), and mitigation guidance (block C2, file hashes, and monitor unexpected outbound connections).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.