Ethical Hacking News
MedusaHVNC Trojan, a new RAT discovered by BlackFog's research team, uses hidden virtual network computing modules to hijack browsers and steal data from users. The malware provides an impressive level of sophistication but still has vulnerabilities that can be exploited to detect and prevent its spread.
MedusaHVNC RAT is a new remote access trojan (RAT) that hijacks browsers and steals sensitive data from users. The malware uses hidden virtual network computing (HVNC) modules to create separate desktops for browsing, allowing operators to remotely control the browser and access user data without being detected. MedusaHVNC RAT has a five-stage infection chain that involves an obfuscated JScript launcher, AutoIt interpreter, config file, encrypted payload, and batch script. The malware is sophisticated, with an operator-friendly interface that allows users to configure sessions before launching them. MedusaHVNC RAT has been marketed as a malware-as-a-service platform through its own website and Telegram channel. The malware supports multiple browsers, including Chrome, Edge, Brave, Firefox, and Telegram, making it easier for attackers to steal credentials and session data.
MedusaHVNC Trojan, a new remote access trojan (RAT) discovered by BlackFog's research team, has been making headlines in recent days. This malware is unique in its approach to hijack browsers and steal sensitive data from users. The MedusaHVNC RAT uses hidden virtual network computing (HVNC) modules to create separate desktops for browsing, allowing operators to remotely control the browser and access user data without being detected.
Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user never touches. However, malware authors have also recognized this feature's potential and exploited it to create MedusaHVNC RAT. The malware uses a five-stage infection chain to infect a machine, involving an obfuscated JScript launcher, AutoIt interpreter, config file, encrypted payload, and batch script.
Once inside, the malware decrypts the payload using a single-byte XOR key, producing a native 64-bit executable that launches into charmap.exe. The loader then runs a series of obfuscation techniques to slow down any attempts at reverse-engineering the sample. BlackFog's own analysis shows that the unpacking process is thoroughly examined, allowing for a detailed understanding of how the malware works.
MedusaHVNC RAT provides an impressive level of polish and sophistication, with an operator-friendly interface that allows users to configure sessions before launching them. The malware leans heavily on legitimate Windows capabilities to execute its functions, making it difficult to detect using traditional security tools. However, BlackFog's research team notes that the network layer is still vulnerable to detection, citing blocking traffic to known command server addresses and alerting on unexpected outbound connections as a starting point for any team looking to act against this malware.
The MedusaHVNC RAT has been marketed through its own website and Telegram channel as a malware-as-a-service platform, offering in-memory execution of .NET and native payloads with AMSI and ETW bypasses. The malware supports Chrome, Edge, Brave, Firefox, and Telegram browsers, making it easier for attackers to steal credentials and session data.
In conclusion, MedusaHVNC RAT represents a significant threat to users' online security. Its sophisticated approach to hijacking browsers and stealing data makes it difficult to detect, but its reliance on legitimate Windows capabilities provides an opportunity for researchers to develop effective countermeasures. As with any malware, vigilance is essential in preventing this type of attack.
Related Information:
https://www.ethicalhackingnews.com/articles/MedusaHVNC-Trojan-Unveiling-the-Hidden-Desktop-Malware-that-Hijacks-Browsers-and-Steals-Data-ehn.shtml
https://securityaffairs.com/196111/malware/medusahvnc-trojan-creates-hidden-desktops-to-hijack-browsers-and-steal-data.html
Published: Mon Jul 27 13:39:04 2026 by llama3.2 3B Q4_K_M