Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Enigma raises $70M to make controlling a robot as easy as adjusting the volume

    July 27, 2026

    Shadow AI agents are multiplying. Here’s how to find and secure them.

    July 27, 2026

    BlackRock tokenization partner Securitize (SECZ) adds SEC investment adviser license amid institutional push

    July 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Enigma raises $70M to make controlling a robot as easy as adjusting the volume
    • Shadow AI agents are multiplying. Here’s how to find and secure them.
    • BlackRock tokenization partner Securitize (SECZ) adds SEC investment adviser license amid institutional push
    • These insect submariners survive depths that should crush them
    • Extreme weather dampens breeding success for marine predators in Tasmania: study
    • Mideast Economic Integration Holds Few Benefits for the U.S.
    • Did PT Barnum march 21 elephants across Brooklyn Bridge to prove it was safe?
    • ‘Dr Death’, Body Worlds creator Gunther von Hagens, dies at 81
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, July 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 27, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hidden desktops are a legitimate Windows capability, often used by specialized software, and occasionally used by malware.

    MedusaHVNC is a remote access trojan (RAT) being sold as malware-as-a-service (MaaS). It is promoted through its own website and a Telegram channel. It was found and analyzed by BlackFog, with the analysis finding a hidden virtual network computing (HVNC) module that opens a legitimate browser on a separate hidden Windows desktop,

    Since it operates from a hidden desktop, its operation is invisible to the user.

    The malware uses a 5-stage infection chain. It starts when the legitimate wscript.exe executes a JScript launcher. The script waits for just over 7.5 seconds and then builds its embedded files under %TEMP%Nx2981Okkr2.

    Several files are written to disc, including an encrypted payload and a .bat in the Startup folder to maintain persistence.

    Windows AutoIT is used to decrypt the payload and start charmap.exe (the Windows character map utility. The loader, now inside charmap.exe, contains two further layers of encryption. “The first applies a 16-byte repeating XOR operation to 1,009,152 bytes from the .data section. The second uses ChaCha20 to decrypt 998,912 bytes of ciphertext with a 32-byte key, a 12-byte nonce, and an initial counter value of 1,” write the researchers.

    Advertisement. Scroll to continue reading.

    That installed final payload ‘is an unsigned PE32+ x86-64 console executable containing a .pay section and the family string MedusaHVNC.’ It communicates with the operator’s C2 at a hardcoded address: 51.89.204.28:4444.

    The operator can create a browser of choice within the hidden desktop from Chrome, Edge, and Firefox. Legitimate Windows functions, including BitBlt, EnumWindows, and PrintWindow support screen and window capture, while SendInput and SetWindowsHookExW are associated with synthetic input and interaction. 

    “Clipboard functions, including OpenClipboard, GetClipboardData, and SetClipboardData, provide another way to move information into or out of the session,” comment the researchers.

    The hidden desktop allows the attacker to take full advantage of legitimate Windows tools without being observed by the user. The C2 is hardcoded into the malware but is relatively safe from observation. The result is a stealthy and persistent RAT.

    The only obvious mitigation is detection of unexpected data exfiltration. Even if the RAT’s operation is out of view in the unknown and hidden desktop, the data must still be exfiltrated from the network. Detection of unexplained data leaving the network is always an indication that something is wrong somewhere.

    Related: Google Antigravity in Crosshairs of Security Researchers, Cybercriminals

    Related: Threat Actor Infests Hotels With New RAT

    Related: New ‘Lobshot’ hVNC Malware Used by Russian Cybercriminals

    Related: TrickBot Targets Outlook, Browser Data

    Desktops Detection Evade hidden Malware MedusaHVNC Windows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Shadow AI agents are multiplying. Here’s how to find and secure them.

    Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

    TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

    When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk

    MCBS Data Breach Affects 1.2 Million Individuals

    GitHub, PyPI add time-absed defenses against supply chain attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Enigma raises $70M to make controlling a robot as easy as adjusting the volume

    July 27, 2026

    Shadow AI agents are multiplying. Here’s how to find and secure them.

    July 27, 2026

    BlackRock tokenization partner Securitize (SECZ) adds SEC investment adviser license amid institutional push

    July 27, 2026

    These insect submariners survive depths that should crush them

    July 27, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Enigma raises $70M to make controlling a robot as easy as adjusting the volume

    July 27, 2026

    Shadow AI agents are multiplying. Here’s how to find and secure them.

    July 27, 2026

    BlackRock tokenization partner Securitize (SECZ) adds SEC investment adviser license amid institutional push

    July 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.