All incidents

MedusaHVNC malware leverages hidden Windows desktops to hijack browsers

malwareopenJul 27, 2026 — Jul 27, 2026
MedusaHVNC Trojan Uses Hidden Desktops to Hijack Browser Sessions

RESEARCHERS at BlackFog have identified a new remote access trojan named MedusaHVNC that creates hidden Windows desktops to silently control victims browsers and harvest session data. The malware is offered as a malware‑as‑a‑service platform, allowing affiliates to deploy it with minimal technical skill. Its discovery highlights a growing trend of threat actors using legitimate Windows features to stay beneath the radar of conventional defences.

MedusaHVNC relies on a hidden virtual network computing module that launches a browser in an invisible desktop session, granting the attacker access to existing profiles, cookies and authenticated states according to BlackFog’s analysis. The infection chain begins with a JScript launcher that writes components to disk, establishes persistence via Startup folder shortcuts and then invokes Windows AutoIT to decrypt the main payload. Obfuscation layers combine XOR and ChaCha20 encryption to conceal communication with the command and control server.

Once active, the trojan uses standard Windows APIs to interact with the hidden desktop, capturing keystrokes, clipboard contents and form inputs without triggering user‑visible windows as noted in technical write‑ups. Its network behaviour is deliberately simple, consisting of periodic HTTPS beacons to a hard‑coded C2 endpoint, which makes the traffic easy to block if detected. BlackFog notes that the malware also disables AMSI and ETW logging to hinder forensic analysis.

Although no CVE identifiers have been assigned to MedusaHVNC, BlackFog’s analysis indicates the trojan is already being rented out on underground forums as part of a MaaS offering. No specific threat actor has been linked to the samples observed so far, but the accessibility of the service suggests it could be adopted by a range of criminal groups seeking to steal banking credentials, corporate logins or personal data.

Defenders should focus on detecting the atypical behaviours that give the malware away, such as unexpected JScript execution from temporary directories or the launch of AutoIT processes with obscure command lines. Monitoring outbound connections for repeated HTTPS requests to unfamiliar domains can reveal the beaconing activity before data is exfiltrated according to BlackFog’s recommendations.

Additional steps include enforcing application control policies that block unsigned JScript and AutoIT binaries, ensuring that PowerShell logging is enabled to capture any attempts to bypass AMSI, and maintaining up‑to‑date threat intelligence feeds that flag the C2 infrastructure associated with MedusaHVNC. By combining network visibility with strict endpoint controls, organisations can reduce the risk of silent browser session hijacking.

Intelligence briefing updated Jul 27, 2026

Root sourcewww.blackfog.com
Timeline Coverage

Swipe to explore timeline