MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user never touches. It’s a niche capability most people never think about, buried deep in how the […]

Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user never touches. It’s a niche capability most people never think about, buried deep in how the operating system manages sessions. Unfortunately, malware authors noticed that too, and BlackFog’s research team just dissected a new remote access trojan called MedusaHVNC that maliciously uses this feature.
“We recently came across a sample of MedusaHVNC, a new remote access trojan (RAT) being sold as malware-as-a-service (MaaS). When we took it apart, we found a hidden virtual network computing (HVNC) module that opens a browser on a separate Windows desktop, out of sight of the victim.” reads the report published by Blackfog. “The browser still runs on the victim’s device, so it can load an existing profile, including cookies and session state. This gives the operator access to live, logged-in sessions while the activity continues to come from the victim’s usual machine.”
Related breach coverage
- MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection2026-07-27
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek.
- Chaos ransomware deploys browser-based msaRAT to evade network detection2026-07-23
Cisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire command-and-control channel through the victim’s own Chrome or Edge browser. The malware […]
- Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials2026-07-26
Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages. No phishing email required. No malicious attachment. Just bad luck about which hotel […]
- Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug2026-07-16
Zoom warns of a critical Windows flaw, tracked as CVE-2026-53412, that could let attackers take over accounts without authentication. Zoom has fixed a critical Windows vulnerability, tracked as CVE-2026-53412 (CVSS score of 9.8) that could allow unauthenticated attackers to hijack user accounts. The flaw affects older versions of Workplace, the Windows VDI Client, and the […]
