Cyber Security News

Hackers Can Use MedusaHVNC to Control Your PC on a Desktop You Cannot See

A newly discovered remote access Trojan called MedusaHVNC lets attackers open a hidden virtual desktop on a victim’s own computer, quietly loading their real browser profile, cookies, and logged-in sessions without any visible sign of intrusion.

Sold as malware-as-a-service through a dedicated website and Telegram channel, MedusaHVNC represents an evolution of hidden VNC (HVNC) techniques long used in banking fraud, now packaged for easy criminal purchase and deployment.

MedusaHVNC Advertised (Source: BlackFog)

According to BlackFog researchers, the hidden VNC malware creates a completely separate Windows desktop with its own explorer.exe process, meaning the victim’s screen shows nothing unusual while the attacker operates freely in the background.

Because the hijacked browser runs on the actual infected machine using its real profile, session cookies, and saved logins, the traffic appears to originate from the victim’s trusted device, bypassing many location- and device-based fraud detections used by banks and other services.

MedusaHVNC Control Your PC Silently

MedusaHVNC is advertised with a “Mem Exec” feature for running .NET and native payloads in memory alongside AMSI and ETW bypasses, plus a “Browser Recovery” function that extracts saved passwords, cookies, and browsing history from Chrome, Edge, Brave, Firefox, and Telegram.

The operator panel lets a buyer select a target application, launch a hidden desktop session, and adjust frame rate and image quality while watching a live view of the compromised browser, similar to how other Medusa-branded malware families have offered turnkey criminal tooling through affiliate models.

MedusaHVNC Secret Desktop (Source: BlackFog)

The infection reportedly unfolds in five stages, beginning when Windows Script Host executes an obfuscated JScript launcher that rebuilds hidden components under a temporary folder and drops a persistence mechanism into the Startup folder so the malware survives a reboot.

An AutoIt interpreter then decrypts the first native payload using a simple XOR key before injecting it into the legitimate Windows Character Map utility (charmap.exe), a classic living-off-the-land technique that helps the malware blend in with trusted system processes an evasion approach also seen in other Medusa-family threats that abuse legitimate tools and signed drivers to dodge detection.

Two more layers of encryption, including XOR and ChaCha20, unpack the final 64-bit payload, which communicates with a hard-coded command-and-control server over raw TCP sockets.

Once active, the payload uses native Windows APIs to fully operate the hidden desktop.

  • Screen and window capture via BitBlt, EnumWindows, and PrintWindow
  • Synthetic input and interaction through SendInput and SetWindowsHookExW
  • Clipboard theft and injection using OpenClipboard, GetClipboardData, and SetClipboardData
  • Targeted support for Chrome, Edge, and Firefox browser sessions

MedusaHVNC’s design mirrors broader trends among Medusa-branded threats, where operators favor living-off-the-land binaries, in-memory execution, and legitimate remote-access tooling to evade endpoint detection while maintaining persistent, low-visibility access, BlackFog said in a report shared with CybersecurityNews.

Security teams should watch for unexpected child processes under charmap.exe, unusual AutoIt script execution, suspicious Startup folder entries, and outbound connections to uncommon high ports, since these behavioral indicators can reveal HVNC activity even when the malware itself evades signature-based detection.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

1 hour ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

1 hour ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

2 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

3 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

3 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

4 hours ago