FILTERING BY: CLEAR FILTER

MedusaHVNC Trojan: Stealthy Browser Hijacking via Windows Hidden Desktops

MedusaHVNC is a sophisticated Remote Access Trojan (RAT) that leverages the legitimate Windows Hidden Desktop API to create an invisible parallel workspace. This allows the malware to instantiate and control browser sessions independently of the primary user interface, enabling the hijacking of active, authenticated sessions for the exfiltration of cookies, credentials, and private data. By operating outside the primary desktop's visual and monitoring scope, MedusaHVNC bypasses traditional user-perceived anomalies and evades many EDR/AV tools that focus on primary UI interaction and window activity.


LINK COPIED TO CLIPBOARD