HVNC (Hidden Virtual Network Computing) is a Windows remote-access malware/tool class that gives an operator control of a separate, invisible desktop session on a compromised host. Unlike conventional VNC, applications and browser activity launched in the hidden desktop are not visible on the victim’s active desktop, enabling covert interactive activity including banking fraud. Observed HVNC payloads support remote screen viewing, simulated keyboard and mouse input, command execution, file browsing, keylogging, browser-data theft, browser redirection, proxying, and persistence. Campaigns have delivered HVNC through phishing lures, trojanized software installers, and malware loaders. A custom HVNC backdoor has targeted Latin American banking and financial-services organizations using fraudulent document-signing, tax-document, and banking lures; it performed security-product discovery, stole Firefox browser data, and established user-level startup persistence. HVNC tooling has also appeared as a secondary payload in cybercriminal operations and in activity attributed to or associated with Kimsuky.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware used by the Kimsuky group not only include custom-made such as AppleSeed and PebbleDash, but also open-source or commercial malware such as XRat, HVNC, Amadey, and Metasploit Meterpreter.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“In some cases, a scheduled task is created, with various names, such as 123456.exe.”
“These DLLs usually act as loaders for malicious batch scripts… @echo off… reg add… start …”
Execution Command and Scripting Interpreter: Python T1059.006 Obfuscated Python payloads
The strings [INJ] === Section-based injection into explorer.exe === and [INJ] Remote thread created in explorer.exe! describe a sequence in which the loader creates a shared memory section via NtCreateSection ... and starts a remote thread via NtCreateThreadEx.
“If the ZIP archives are opened, they initiate an infection chain leading to the installation of PureRAT or another payload such as a HVNC.”
“The archives usually contain an executable, which is then used to sideload a malicious DLL… Haihaisoft PDF Reader or an old version of Microsoft Excel… renamed version of the Foxit PDF reader for sideloading… malicious DLLs included: oledlg.dll, msimg32.dll, version.dll, and profapi.dll.”
Defense Evasion Obfuscated Files or Information T1027 Kramer Python obfuscator, .pyc as .py
“phishing emails… masquerading as job offers… attackers renamed the executable to masquerade as something else… adobereader.exe… Salary and Benefits.exe… After the persistence mechanism… masquerading as ChromeUpdate.”
To run the HVNC payload covertly, the loader is equipped to inject the DLL into explorer.exe using a technique known as section-based injection.
“Tạo tiến trình InstallUtil.exe ngầm (ẩn cửa sổ) … target_path = …\InstallUtil.exe”
MITRE ATT&CK Mapping ... Execution Regsvr32 T1218.010 DLL registration via regsvr32 /s
Windows supports the CreateDesktop() API that can create a hidden desktop window with its own corresponding explorer.exe process. All applications running on the hidden desktop window, such as a hidden VNC (hVNC) session, will be invisible to other desktops windows.
“creates a hidden directory under %LOCALAPPDATA%\Google Chrome… attrib +h +s”
In addition, Windows supports the CreateDesktop() API that can create a hidden desktop window with its own corresponding explorer.exe process. All applications running on the hidden desktop window, such as a hidden VNC (hVNC) session, will be invisible to other desktops windows.
Operators can use HVNC to control a hidden browser session, run a keylogger, take screenshots, and manage files remotely.
Windows supports the CreateDesktop() API that can create a hidden desktop window with its own corresponding explorer.exe process. All applications running on the hidden desktop window, such as a hidden VNC (hVNC) session, will be invisible to other desktops windows.
“The archives usually contain an executable, which is then used to sideload a malicious DLL… Haihaisoft PDF Reader or an old version of Microsoft Excel… renamed version of the Foxit PDF reader for sideloading… malicious DLLs included: oledlg.dll, msimg32.dll, version.dll, and profapi.dll.”
In our analyzed sample, command-and-control (C&C) communication starts with the following magic: The snippet below shows that some values are hardcoded into the executable, others are generated from MachineGuid or randomly generated.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom 64-bit hidden-virtual-network-computing backdoor delivered through fake DocuSign, NFe/DANFE tax-document, and banking phishing lures. It provides attackers with a hidden desktop for remote control, screen capture, simulated keyboard and mouse input, keylogging, Firefox cookie/history/permission theft, browser redirection, AV/EDR discovery, and persistent C2 communications. It persists by copying itself to %APPDATA%\Roaming\Programs\Common\ as AppUpdateHelper.exe and creating a Startup-folder shortcut. Builds identify themselves over C2 with an HVNC- handshake and VERSION:1.2.0.4.71.
A custom Windows hidden-virtual-network-computing backdoor providing persistent, concealed remote control through a hidden desktop. It captures screens, simulates mouse and keyboard input, monitors keystrokes, steals Firefox cookies, browsing history, and permissions data, performs AV/EDR-process discovery, supports operator-directed browser redirection, and communicates using a custom raw-TCP protocol self-identified as "HVNC-".
A Go-based remote access trojan with hidden virtual network computing capability that provides remote control, command execution, file browsing, keylogging, proxying, in-memory execution, persistence, and covert desktop interaction.
A Hidden Virtual Network Computing payload that creates an invisible desktop session, allowing attackers to browse, access accounts, and interact with authenticated sessions without anything appearing on the victim’s visible screen. The article notes it is primarily associated with financial fraud operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.