securityaffairs.com 7/27/2026, 6:51:51 PM · external

MedusaHVNC Trojan Uses Hidden Desktops to Hijack Browser Sessions

MedusaHVNC Trojan Uses Hidden Desktops to Hijack Browser Sessions
Developing story malware 2 articles tracked
MedusaHVNC malware leverages hidden Windows desktops to hijack browsers
CyberSIXT Evidence Panel
Primary Source blackfog.com

THE MedusaHVNC Trojan is a new malware-as-a-service (MaaS) that exploits hidden Windows desktops to remotely control browsers and steal sensitive data. Discovered by BlackFog, this remote access trojan (RAT) utilizes a hidden virtual network computing (HVNC) module to open browsers in an unseen environment, gaining access to victims' existing profiles, cookies, and session states.

The malware comprises several sophisticated techniques, including in-memory execution, AMSI/ETW bypasses, and obfuscated payloads that leverage legitimate Windows features for its operations. The communication with its command server is straightforward, enabling easy blocking by cybersecurity measures. BlackFog recommends monitoring outbound network traffic as a primary defense against such threats.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline