Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The chain starts with obfuscated JScript... Running without a visible window, the AutoIt component decrypts the dropped payload with a single-byte XOR key, 0xAE ... The loader now running inside charmap.exe contains two further encryption layers before the final payload.
These include an AutoIt interpreter named eepcxlhgdz.exe , a configuration file, and an encrypted payload with no file extension named zorsxklxfehdoals .
The public sandbox process tree shows charmap.exe as a child of the AutoIt process, and the loader is injected into it, using the trusted system binary as a host for the payload.
The loader, now inside charmap.exe, contains two further layers of encryption. The first applies a 16-byte repeating XOR operation ... The second uses ChaCha20 to decrypt 998,912 bytes of ciphertext...
The AutoIt stage then starts C:\Windows\System32\charmap.exe , the standard Windows Character Map utility... using the trusted system binary as a host for the payload.
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection ... a hidden virtual network computing (HVNC) module that opens a legitimate browser on a separate hidden Windows desktop. Since it operates from a hidden desktop, its operation is invisible to the user.
SendInput and SetWindowsHookExW are associated with synthetic input and interaction.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealthy remote access trojan sold as malware-as-a-service that uses hidden Windows desktops to launch legitimate browsers invisibly, enabling persistent covert remote access, screen/window capture, synthetic input, clipboard interaction, and data exfiltration via a hardcoded C2.
A remote access trojan sold as malware-as-a-service that provides hidden virtual network computing capabilities. It opens browsers on a separate hidden Windows desktop to hijack live logged-in sessions, access cookies and session state, recover browser data, execute payloads in memory, and communicate with a hard-coded C2 over a custom TCP protocol.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.