logo

Behind Closed Doors: The Rise of Hidden Malicious Remote Access

ID: 07bcf6b4-fce2-561e-b32f-a8d1ad6cc6fb

STIX ID: report--07bcf6b4-fce2-561e-b32f-a8d1ad6cc6fb

Feed Name: Cybereason Blog

Threat Score
70/100

Date Published: 2024-05-06

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason analyzes the emergence and abuse of hidden remote-access techniques — hidden VNC (hVNC) and hidden RDP (hRDP) — as integrated features in modern RATs (Xeno, XWorm, Venom, Pandora). The report demonstrates how attackers create invisible desktops or covert RDP sessions to maintain stealthy persistence, perform data exfiltration and lateral movement, documents behavioral indicators (process injection, multiple explorer.exe instances, unusual command-line flags, unexpected RDP users), shows marketplace availability of these tools, and recommends detection and prevention controls using EDR, behavioral analytics, and application/variant/fileless protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.