static-urls · Crawled Jul 29, 2026

MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions | BlackFog

4 IoCs
Read original article ↗

AI Summary

MedusaHVNC is a newly identified remote access trojan (RAT) distributed as malware-as-a-service (MaaS) that enables attackers to access live, logged-in browser sessions via a hidden virtual desktop on Windows systems. The infection chain begins with an obfuscated JScript that drops and executes multiple components, including an AutoIt-based decryptor and a layered unpacking routine, ultimately loading a 64-bit payload. The final payload establishes a connection to a hard-coded command-and-control (C2) server and enables screen capture, synthetic input, and clipboard manipulation to interact with the hidden desktop session. This allows operators to stealthily monitor and control active user sessions without detection.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
IP 51[.]89[.]204[.]28 Details →
Filename zorsxklxfehdoals Details →
Filename AFLlvOscPj.bat Details →
Filename eepcxlhgdz.exe Details →