MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions | BlackFog
AI Summary
MedusaHVNC is a newly identified remote access trojan (RAT) distributed as malware-as-a-service (MaaS) that enables attackers to access live, logged-in browser sessions via a hidden virtual desktop on Windows systems. The infection chain begins with an obfuscated JScript that drops and executes multiple components, including an AutoIt-based decryptor and a layered unpacking routine, ultimately loading a 64-bit payload. The final payload establishes a connection to a hard-coded command-and-control (C2) server and enables screen capture, synthetic input, and clipboard manipulation to interact with the hidden desktop session. This allows operators to stealthily monitor and control active user sessions without detection.
AI-extracted · verify before operational use