Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Covid vaccines don’t raise your risk of miscarriage – Full Fact

    July 27, 2026

    Guyana Ferry Tragedy Exposes Political Rifts in Oil-Rich Country

    July 27, 2026

    Poland asks US to extradite its ex-justice minister – POLITICO

    July 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Covid vaccines don’t raise your risk of miscarriage – Full Fact
    • Guyana Ferry Tragedy Exposes Political Rifts in Oil-Rich Country
    • Poland asks US to extradite its ex-justice minister – POLITICO
    • Why Restarting a Nuclear Power Plant Can Be Much Harder Than Expected
    • 3 Best Smart Ring Models: Oura, RingConn, and Samsung (2026)
    • New GitHub, PyPI Policies Boost Supply Chain Security
    • Strategy Skips Bitcoin Again, Buys Back $25M Of STRC Preferred
    • Cheetahs reintroduced to Zambia’s Greater Luangwa Ecosystem
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, July 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 27, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hidden desktops are a legitimate Windows capability, often used by specialized software, and occasionally used by malware.

    MedusaHVNC is a remote access trojan (RAT) being sold as malware-as-a-service (MaaS). It is promoted through its own website and a Telegram channel. It was found and analyzed by BlackFog, with the analysis finding a hidden virtual network computing (HVNC) module that opens a legitimate browser on a separate hidden Windows desktop,

    Since it operates from a hidden desktop, its operation is invisible to the user.

    The malware uses a 5-stage infection chain. It starts when the legitimate wscript.exe executes a JScript launcher. The script waits for just over 7.5 seconds and then builds its embedded files under %TEMP%Nx2981Okkr2.

    Several files are written to disc, including an encrypted payload and a .bat in the Startup folder to maintain persistence.

    Windows AutoIT is used to decrypt the payload and start charmap.exe (the Windows character map utility. The loader, now inside charmap.exe, contains two further layers of encryption. “The first applies a 16-byte repeating XOR operation to 1,009,152 bytes from the .data section. The second uses ChaCha20 to decrypt 998,912 bytes of ciphertext with a 32-byte key, a 12-byte nonce, and an initial counter value of 1,” write the researchers.

    Advertisement. Scroll to continue reading.

    That installed final payload ‘is an unsigned PE32+ x86-64 console executable containing a .pay section and the family string MedusaHVNC.’ It communicates with the operator’s C2 at a hardcoded address: 51.89.204.28:4444.

    The operator can create a browser of choice within the hidden desktop from Chrome, Edge, and Firefox. Legitimate Windows functions, including BitBlt, EnumWindows, and PrintWindow support screen and window capture, while SendInput and SetWindowsHookExW are associated with synthetic input and interaction. 

    “Clipboard functions, including OpenClipboard, GetClipboardData, and SetClipboardData, provide another way to move information into or out of the session,” comment the researchers.

    The hidden desktop allows the attacker to take full advantage of legitimate Windows tools without being observed by the user. The C2 is hardcoded into the malware but is relatively safe from observation. The result is a stealthy and persistent RAT.

    The only obvious mitigation is detection of unexpected data exfiltration. Even if the RAT’s operation is out of view in the unknown and hidden desktop, the data must still be exfiltrated from the network. Detection of unexplained data leaving the network is always an indication that something is wrong somewhere.

    Related: Google Antigravity in Crosshairs of Security Researchers, Cybercriminals

    Related: Threat Actor Infests Hotels With New RAT

    Related: New ‘Lobshot’ hVNC Malware Used by Russian Cybercriminals

    Related: TrickBot Targets Outlook, Browser Data

    Desktops Detection Evade hidden Malware MedusaHVNC Windows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New GitHub, PyPI Policies Boost Supply Chain Security

    Shadow AI agents are multiplying. Here’s how to find and secure them.

    Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

    TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

    When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk

    MCBS Data Breach Affects 1.2 Million Individuals

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Covid vaccines don’t raise your risk of miscarriage – Full Fact

    July 27, 2026

    Guyana Ferry Tragedy Exposes Political Rifts in Oil-Rich Country

    July 27, 2026

    Poland asks US to extradite its ex-justice minister – POLITICO

    July 27, 2026

    Why Restarting a Nuclear Power Plant Can Be Much Harder Than Expected

    July 27, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Covid vaccines don’t raise your risk of miscarriage – Full Fact

    July 27, 2026

    Guyana Ferry Tragedy Exposes Political Rifts in Oil-Rich Country

    July 27, 2026

    Poland asks US to extradite its ex-justice minister – POLITICO

    July 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.