Researchers detailed MedusaHVNC, a malware-as-a-service remote access trojan that gives attackers covert control of infected Windows systems by creating an invisible desktop and launching legitimate browsers outside the victim’s view. The malware lets operators abuse the victim’s existing browser profiles, cookies, and live authenticated sessions, making malicious activity appear to come from the user’s own device. Analysts said the payload supports typical hidden VNC functions including screen capture, synthetic keyboard and mouse input, window interaction, and clipboard access, with references to Chrome, Edge, and Firefox.
Analysis of a recent sample found a five-stage infection chain starting with wscript.exe running an obfuscated JScript launcher, followed by files dropped into the TEMP directory, persistence via a Startup-folder batch file, and AutoIt-based components that inject a loader into charmap.exe before unpacking the final unsigned 64-bit payload. The malware contains the MedusaHVNC family string and communicates over a custom TCP protocol with a hard-coded command-and-control server at 51.89.204.28:4444. Researchers said defenders should focus on outbound traffic monitoring, blocking known infrastructure and file hashes, and watching for unexpected data exfiltration because stolen information must still leave the network.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
SecurityWeek reported on BlackFog's findings about MedusaHVNC, highlighting its use of hidden Windows desktops to invisibly launch browsers and maintain covert access while recommending detection through monitoring for unexpected data exfiltration.
BlackFog published an analysis of a newly observed MedusaHVNC malware-as-a-service remote access trojan, describing its hidden desktop technique, five-stage infection chain, and command-and-control server at 51.89.204.28:4444.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourceblackfog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.