MedusaHVNC is a malware-as-a-service RAT that uses a hidden Windows desktop to run a browser and interact with the system without the user seeing it. BlackFog found that it relies on a multi-stage infection chain, encrypted payloads, persistence in the Startup folder, and a hardcoded C2 address to stay stealthy and persistent. #MedusaHVNC #BlackFog #wscript.exe #charmap.exe
Keypoints
- MedusaHVNC is sold as malware-as-a-service through a website and Telegram channel.
- It uses a hidden virtual network computing module on a separate Windows desktop.
- The infection chain begins with wscript.exe and a JScript launcher.
- It writes files to %TEMP% and the Startup folder to maintain persistence.
- The RAT uses encrypted layers, hardcoded C2 communication, and Windows functions for stealthy control.
Read More: https://www.securityweek.com/medusahvnc-malware-uses-hidden-windows-desktops-to-evade-detection/