MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
ID: d3a2066d-fe5a-53eb-a0e4-38edcdee26fa
STIX ID: report--d3a2066d-fe5a-53eb-a0e4-38edcdee26fa
Feed Name: Security Affairs
MedusaHVNC is a malware-as-a-service remote access trojan that abuses legitimate Windows hidden desktop functionality to launch real browsers out of view and hijack live sessions (cookies, passwords, history). The report details an infection chain (obfuscated JScript launcher → AutoIt decryption → loader injected into charmap.exe → ChaCha20-unpacked payload), in-memory execution with AMSI/ETW bypasses, HVNC capture/input techniques, baked-in C2 (51.89.204.28:4444), and mitigation guidance (block C2, file hashes, and monitor unexpected outbound connections).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
