Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » New MedusaHVNC Malware Uses Hidden Windows Desktop to Steal Browser Data

New MedusaHVNC Malware Uses Hidden Windows Desktop to Steal Browser Data

Last updated:July 28, 2026
Human Written
  • MedusaHVNC is a malware-as-a-service RAT that is able to create a hidden Windows desktop to exploit browsers and to capture live session information without detection.

  • The malware works with a five-stage infection scheme, it has many encryption layers to avoid detection by security systems.

  • It allows the attacker to access browser sessions, to steal cookies and passwords, and to exfiltrate information from infected computers running on Windows.

New MedusaHVNC Malware Uses Hidden Windows Desktop to Steal Browser Data

A newly discovered remote access trojan is using a clever trick to stay hidden from victims. The malware, called MedusaHVNC, creates a secret desktop on infected Windows computers; this hidden desktop is completely invisible to the user. Attackers can then open browsers and access accounts without the victim ever knowing.

Security researchers discovered and analyzed this dangerous malware. MedusaHVNC operates as a malware-as-a-service, meaning anyone can buy it. The developers promote it through their own website and a Telegram channel. This makes powerful hacking tools available to criminals with little technical skill.

The very name of the malware is derived from its essential point, Hidden Virtual Network Computing (HVNC). The essence of HVNC is that hackers can access a computer remotely without the victim noticing any suspicious activity.

At the same time, the hidden browser uses the browser profiles and cookies of users. Therefore, any suspicious activity appears to come from the device of the victim. Consequently, this bypasses many security systems that rely on location and device checks.

How the Infection Unfolds

MedusaHVNC uses a five-stage infection chain to compromise systems. The process begins with a JScript launcher. The legitimate Windows program wscript.exe runs this script. The script then waits for about 7.5 seconds before taking further action and this delay helps the malware avoid detection by sandbox environments.

The script then builds hidden files inside a temporary folder on the computer of the victim. These files include an encrypted payload and a batch file. The batch file is sent into the Startup folder, thus ensuring the persistence of malware. As a result, the infection survives even after the system restarts.

After that, the next stage utilizes AutoIt, a legitimate Windows automation tool, which decrypts the first payload using a simple XOR key. It then starts the Windows Character Map utility, charmap.exe. The malware injects its code into this trusted system process. This technique helps the malware blend in with normal system activity.

The loader inside charmap.exe then unpacks two more encryption layers. The first layer uses a repeating XOR operation on over one million bytes of code. The second layer employs the ChaCha20 cipher to decrypt nearly another million bytes. These multiple layers make analysis and detection much harder for security tools.

The final payload is an unsigned executable that operates with a command-and-control server at a hardcoded address – and the server operates at 51.89.204.28 on port 4444. The malware uses raw TCP sockets to send commands and receive instructions.

What Attackers Can Do

Once active, MedusaHVNC gives attackers complete control over the hidden desktop. Operators can launch any of three major browsers, including Chrome, Edge, or Firefox. The attacker can see everything displayed in these browsers. They can also take screenshots and capture window contents using legitimate Windows functions like BitBlt and PrintWindow.

Attackers can interact with the browser using synthetic keyboard and mouse input. This capability lets them navigate websites and click buttons. The malware also uses clipboard functions to steal or inject data. It can grab passwords, cookies, and browsing history from the compromised browser profiles.

The hidden desktop technique makes this malware particularly dangerous. The victim never sees the attacker’s activity on their screen. The browser runs on the same device using the same IP address. This means security systems that check for unusual locations cannot detect the breach. The activity appears completely normal to most monitoring tools.

The only clear way to detect MedusaHVNC is by monitoring outbound network traffic. Even though the malware operates in a hidden desktop, the stolen data must still leave the network. Organizations should watch for unexpected data transfers – they should also block known command-and-control infrastructure.

The Malware-as-a-Service Threat

The sale of MedusaHVNC as a service dramatically increases the risk. Cybercriminals do not need advanced technical skills to use it. The seller advertises features like memory execution and browser recovery. 

These features allow the extraction of passwords and browsing history, and the tool supports multiple browsers, including Chrome, Edge, Brave, Firefox, and Telegram. The abuse of Telegram by cybercriminals is also seen in a campaign targeting Middle East governments.

The seller claims to include AMSI and ETW bypasses, making detection even harder. This accessibility means more attackers can target organizations worldwide. Security experts recommend that companies restrict AutoIt usage and monitor for charmap.exe injections. They also advise watching for suspicious entries in the Startup folder.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.