MedusaHVNC: The MaaS Trojan That Exploits Hidden Windows Desktops to Hijack Browsers
MedusaHVNC is a MaaS trojan exploiting HVNC to hijack authenticated browser sessions on hidden Windows desktops, stealing cookies and credentials stealthily.
Illustrative image generated with AI
Introduction
On July 27, 2026, researchers at BlackFog uncovered a new cyber threat: MedusaHVNC, a remote access trojan (RAT) distributed as Malware-as-a-Service through a dedicated website and a Telegram channel. The distinctive feature of this malware lies in its use of the HVNC (Hidden Virtual Network Computing) technique, which allows it to launch browsers on a separate, invisible Windows desktop, taking control of authenticated sessions without the user's knowledge. With a high severity profile, MedusaHVNC combines stealth, abuse of legitimate system components, and a business model that facilitates its spread, posing a significant challenge to the security of Windows environments.
Technical Analysis
MedusaHVNC’s infection chain consists of multiple stages designed to evade security controls. The attack begins with an obfuscated JScript script that, once executed (typically via social engineering), calls the AutoIt interpreter. This legitimate scripting tool, often abused in malicious contexts, decodes and injects the payload into the charmap.exe (Character Map) process, a normally harmless system executable. The execution takes place entirely in memory, without writing to disk, thanks to techniques that bypass AMSI (Antimalware Scan Interface) and ETW (Event Tracing for Windows).
The code is protected by two layers of encryption: first XOR, followed by ChaCha20, reflecting a focused effort on obfuscation. The HVNC module leverages a native Windows feature to create a hidden desktop, invisible to the user, where the most common browsers (Chrome, Edge, Firefox, Brave) are launched with their original profiles and cookies. The operator, connected to the C2 server at 51.89.204.28:4444 via a custom protocol based on native Windows APIs, can thus view private pages, actively operate, and steal data (passwords, cookies, history) even from the Telegram app.
Remote control relies exclusively on legitimate Windows APIs, such as BitBlt and PrintWindow for screen capture, EnumWindows to find windows, SendInput and SetWindowsHookExW to simulate clicks and keystrokes, and clipboard interfaces. This choice makes the malware's behavior nearly indistinguishable from a legitimate remote administration tool, bypassing many behavioral defenses. Persistence is ensured by a batch script placed in the Startup folder, surviving reboots.
Impact
MedusaHVNC allows access to already authenticated web sessions, reading private content and performing actions on behalf of the victim (e.g., transactions, sending messages, changing settings). The stolen data—credentials, cookies, clipboard contents—can be used for further compromise or sold on the black market. The invisibility provided by the hidden desktop and the abuse of trusted processes make the infection difficult to detect even for experienced users, raising the risk of prolonged damage. The MaaS platform, accessible to criminals with limited skills, amplifies the threat of large-scale campaigns.
Mitigation
Countermeasures, though not trivial, can limit the trojan's effectiveness:
- Block traffic to IP
51.89.204.28on port4444at the firewall and proxy level, since the C2 infrastructure is hardcoded. - Monitor for abnormal process chains: in particular, the launch of
charmap.exeby AutoIt or from non-interactive executables should trigger an alert. - Detect suspicious use of APIs like
BitBlt,EnumWindows, orPrintWindowby processes without a graphical interface (e.g., with low integrity level and no active windows). - Restrict the execution of non-essential scripting interpreters (such as AutoIt) via Application Control policies.
- Keep systems up to date, enable multi-factor authentication, and train users not to open suspicious attachments.
FAQ
1. Can MedusaHVNC infect recent versions of Windows?
Yes, the trojan exploits native multiple-desktop features present in all modern Windows versions. It does not rely on specific vulnerabilities but on deception to achieve execution of the initial script.
2. Does using a password manager protect me from credential theft?
Only partially. MedusaHVNC steals session cookies, clipboard data, and credentials already stored in browsers, which may also involve the password manager if integrated. Moreover, it accesses already active sessions, so MFA can be bypassed if the user has already logged in.
3. Why is this malware difficult for antivirus software to detect?
Because it operates in memory without touching the disk (fileless), hides within a trusted system process (charmap.exe), and uses only legitimate Windows APIs for remote control, mimicking approved administration tools. Only a thorough contextual analysis can distinguish its anomalous behavior.
Sources
This article is an original reworking based on the sources below.




