In brief: MedusaHVNC uses hidden Windows desktops to conceal remote access, making network monitoring critical for detection.
The Remote Access Trojan MedusaHVNC is distributed as malware-as-a-service and installs itself via a five-stage infection chain that permanently compromises systems. The malware uses Windows desktops invisible to the attacker to hide activities from the legitimate user.
Security researchers from BlackFog have analyzed how MedusaHVNC functions. The malware is offered as a paid service via its own website and a Telegram channel. The infection begins with the execution of a JScript launcher by wscript.exe, followed by a delay of approximately 7.5 seconds. The script deposits files in the %TEMP%Nx2981Okkr2 directory and writes a batch file to the Autostart folder to establish persistence.
The payload is injected into the charmap.exe process via Windows AutoIT and protected by two encryption layers: first a 16-byte XOR operation on 1,009,152 bytes of the .data section, then ChaCha20 decryption with a 32-byte key and 12-byte nonce. The final PE32+ file connects to the command server address 51.89.204.28 on port 4444.
Via its Hidden-VNC module, MedusaHVNC creates a separate Windows desktop that is invisible to the logged-in user. From there, attackers can launch browsers such as Chrome, Edge, or Firefox and execute any actions. The software uses legitimate Windows APIs such as BitBlt, EnumWindows, PrintWindow, SendInput, and SetWindowsHookExW for screen captures and user interactions. For data exfiltration, it also uses clipboard functions (OpenClipboard, GetClipboardData, SetClipboardData).
Since all activities take place on the hidden desktop, they remain invisible on the main screen to the user. Detection via the graphical user interface is therefore not possible. However, infection can be detected through monitoring network traffic, as unusual data flows from the system remain measurable.
Source: www.it-daily.net · Published 1 August 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.