MedusaHVNC Malware Hijacks Browser Sessions via Hidden Windows Desktops
A high-severity remote access trojan called MedusaHVNC uses hidden Windows desktops to silently control victims' logged-in browsers without their knowledge. The malware is delivered through obfuscated JScript, uses AutoIt scripting and charmap.exe process injection, and employs multi-layer encryption including XOR and ChaCha20 to conceal its payload. Once active, it connects to a command-and-control server at 51.89.204.28:4444 and launches Chrome, Edge, or Firefox on a separate desktop invisible to the user, using the victim's existing cookies, sessions, and IP address. Because all activity originates from the legitimate device and profile, security controls relying on impossible-travel or IP-based anomaly detection are largely bypassed. The malware is offered as a Malware-as-a-Service operation, allowing attackers to steal web sessions, clipboard data, and saved browser credentials without triggering user awareness.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in