THE MedusaHVNC Trojan is a new malware-as-a-service (MaaS) that exploits hidden Windows desktops to remotely control browsers and steal sensitive data. Discovered by BlackFog, this remote access trojan (RAT) utilizes a hidden virtual network computing (HVNC) module to open browsers in an unseen environment, gaining access to victims' existing profiles, cookies, and session states.
The malware comprises several sophisticated techniques, including in-memory execution, AMSI/ETW bypasses, and obfuscated payloads that leverage legitimate Windows features for its operations. The communication with its command server is straightforward, enabling easy blocking by cybersecurity measures. BlackFog recommends monitoring outbound network traffic as a primary defense against such threats.