MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

https://www.securityweek.com/wp-content/uploads/2025/08/Infostealer-Malware.jpg

Hidden desktops are a legitimate Windows capability, often used by specialized software, and occasionally used by malware.

MedusaHVNC is a remote access trojan (RAT) being sold as malware-as-a-service (MaaS). It is promoted through its own website and a Telegram channel. It was found and analyzed by BlackFog, with the analysis finding a hidden virtual network computing (HVNC) module that opens a legitimate browser on a separate hidden Windows desktop,

Since it operates from a hidden desktop, its operation is invisible to the user.

The malware uses a 5-stage infection chain. It starts when the legitimate wscript.exe executes a JScript launcher. The script waits for just over 7.5 seconds and then builds its embedded files under %TEMP%\Nx2981Okkr2\.

Several files are written to disc, including an encrypted payload and a .bat in the Startup folder to maintain persistence.

Windows AutoIT is used to decrypt the payload and start charmap.exe (the Windows character...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more