MedusaHVNC is a Windows remote access trojan sold as a malware-as-a-service offering. Its defining capability is hidden virtual network computing (HVNC): it creates a concealed Windows desktop and launches a legitimate browser within that hidden session, allowing an operator to interact with the victim’s real browser profile, cookies, and already authenticated sessions without visible on-screen activity. This design enables covert abuse of trusted victim environments and can facilitate account takeover and fraud by making activity appear to originate from the victim’s own device.
The malware has been observed with browser and application recovery features that extract saved passwords, cookies, browsing history, and session data from major browsers, and it also supports clipboard interaction, screen and window capture, and synthetic keyboard and mouse input through native Windows APIs. Advertised functionality also includes in-memory execution of additional .NET and native payloads together with AMSI and ETW bypasses, indicating a broader post-compromise utility beyond browser session abuse.
Observed execution on Windows uses a multi-stage chain beginning with an obfuscated JScript launcher executed by Windows Script Host, followed by AutoIt-based staging and decryption. Persistence is established through the Windows Startup folder. A native loader is then injected into a legitimate Windows process, after which additional unpacking layers, including XOR-based decoding and ChaCha20 decryption, reveal the final payload. The malware communicates with its operator over a custom TCP-based command-and-control protocol implemented with native Windows networking functions.
MedusaHVNC is associated with stealth-oriented tradecraft including hidden desktop operation, process injection, living-off-the-land process abuse, layered obfuscation, and in-memory execution. Reported targeting is consistent with theft and abuse of browser credentials and authenticated sessions on Windows endpoints, with particular relevance to financial services, e-commerce, and any environment where browser-based authenticated access can be monetized or operationally exploited.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
That executable launches straight into charmap.exe, yes, the built-in Windows Character Map utility that ships on every machine.
Injection via charmap.exe : le loader est injecté dans C:\Windows\System32\charmap.exe
Déchiffrement AutoIt : déchiffrement du payload via XOR à un octet (0xAE)... Déchiffrement en couches : XOR répétitif sur 16 octets... puis ChaCha20
Injection via charmap.exe : le loader est injecté dans C:\Windows\System32\charmap.exe (binary hijacking de confiance)
synthetic mouse clicks and keystrokes come through SendInput and SetWindowsHookExW.
Ce navigateur s’exécute sur la machine de la victime et charge les profils existants (cookies, sessions actives), permettant à l’opérateur d’accéder à des sessions authentifiées en temps réel
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan with an HVNC module that opens a hidden browser session on a separate invisible Windows desktop, allowing operators to hijack authenticated sessions, steal cookies, passwords and browsing history, execute .NET and native payloads in memory, and communicate with C2 over custom TCP.
A remote access trojan sold as malware-as-a-service that creates hidden Windows desktops to launch and remotely control real browsers outside the victim’s view. It steals passwords, cookies, browsing history, and abuses existing logged-in browser sessions for account takeover and data theft. The malware uses multi-stage delivery, AutoIt-assisted decryption, process injection into charmap.exe, and legitimate Windows APIs for screen capture, input simulation, window management, and clipboard access to evade detection.
A malware-as-a-service hidden VNC remote access trojan that creates a separate hidden Windows desktop, hijacks the victim’s real browser sessions, steals passwords/cookies/history, supports in-memory payload execution with AMSI/ETW bypasses, persists via the Startup folder, injects into charmap.exe, and communicates with a hard-coded C2 over raw TCP sockets.
A stealthy remote access trojan sold as malware-as-a-service that uses hidden Windows desktops to launch legitimate browsers invisibly, enabling persistent covert remote access, screen/window capture, synthetic input, clipboard interaction, and data exfiltration via a hardcoded C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.