MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek.
Hidden desktops are a legitimate Windows capability, often used by specialized software, and occasionally used by malware.
MedusaHVNC is a remote access trojan (RAT) being sold as malware-as-a-service (MaaS). It is promoted through its own website and a Telegram channel. It was found and analyzed by BlackFog, with the analysis finding a hidden virtual network computing (HVNC) module that opens a legitimate browser on a separate hidden Windows desktop,
Since it operates from a hidden desktop, its operation is invisible to the user.
Source: https://www.securityweek.com/medusahvnc-malware-uses-hidden-windows-desktops-to-evade-detection/
Related breach coverage
- MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data2026-07-27
MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user never touches. It’s a niche capability most people never think about, buried deep in how the […]
- New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication2026-07-21
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek.
- Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day2026-07-28
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
- OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider2026-07-23
AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek.
