MedusaHVNC: Remote Control of Logged-in Browsers on Hidden Windows Desktops
1. Basic Information
- Article Title: MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
- Publisher: SecurityWeek
- Publication Date: 2026-07-27
- Original Article: https://www.securityweek.com/medusahvnc-malware-uses-hidden-windows-desktops-to-evade-detection/
- Primary Source: https://www.blackfog.com/medusahvnc-a-hidden-desktop/
-
Related Entities: MedusaHVNC, MaaS, HVNC, JScript, AutoIt,
charmap.exe, ChaCha20, Chrome/Edge/Firefox - Severity: High
-
IOCs:
51.89.204.28:4444,%TEMP%\Nx2981Okkr2\,AFLlvOscPj.bat,zorsxklxfehdoals
2. Executive Summary
This is a RAT that uses JScript, AutoIt, charmap.exe injection, and multi-layer decryption to open logged-in browsers on a hidden Windows desktop invisible to the user. It controls existing cookies and sessions using the victim device’s original IP address.
3. Attack Flow
-
wscript.exeruns an obfuscated JScript file and waits for 7,584 milliseconds. - It extracts the AutoIt execution system, configuration, and encrypted payload to
%TEMP%\Nx2981Okkr2\. - It places
AFLlvOscPj.batin the Startup folder for persistence. - AutoIt decrypts the payload using single-byte XOR
0xAE. - It starts the legitimate
C:\Windows\System32\charmap.exeand injects the loader into it. - It decrypts the final x64 PE file using 16-byte repeating XOR and ChaCha20.
- It makes a custom TCP connection to
51.89.204.28:4444. - It creates another hidden desktop and launches Chrome, Edge, or Firefox.
- It captures screens using
BitBltandPrintWindow, sends inputs usingSendInput, and moves data using the Clipboard API. - It uses cookies and sessions from existing browser profiles to control user accounts.
4. Attacker Position and Execution Location
- The attacker uses a MaaS operation panel and C2 server.
- The loader and HVNC run on the Windows device, and the browser runs on a separate desktop invisible to the user, but on the same device, IP, and profile.
- The initial delivery vector is unknown in the primary source.
5. Visibility for Victims and Administrators
- The user cannot see the browser controlled by the attacker on their screen.
- Observable points include Startup BAT, AutoIt,
AutoIt → charpmap.exe, screen capture, and C2 communication. - To SaaS platforms, it looks like a normal device, a normal IP, and existing cookies, making “Impossible Travel” detections less effective.
6. Success and Failure Conditions
- Success: JScript/AutoIt execution, Startup writing, injection permission, existing browser profile, and C2 reachability.
- Failure: WSH/AutoIt restrictions, application control, injection detection, Startup monitoring, C2 blocking, and cookie protection/re-authentication.
7. What Happens on Success
Attackers can control and steal logged-in web sessions, cookies, clipboard data, screen contents, and saved browser information without the user noticing. The sellers also advertise AMSI/ETW bypass, memory execution, and browser recovery, but analysis samples do not always confirm all features.
8. Observable Logs
- Email: Initial delivery unknown. Check for suspicious JScript attachments or URLs.
-
Proxy/SWG/DNS:
51.89.204.28:4444, custom TCP traffic separate from the browser, and web access from the hidden desktop. -
Endpoint/EDR:
wscript.exe, 7.5-second wait, TEMP extraction, Startup BAT, AutoIt,charmap.exeinjection, and screen/clipboard/input APIs. - Identity/IdP: Use of existing sessions, abnormal operations from the same IP/device, and prompts for re-authentication or high-risk actions.
- SaaS/Cloud: Unusual volume of operations, setting changes, file downloads, and payment or email actions.
- Network: Hardcoded C2, long-duration TCP connections, and periodic traffic associated with screen updates.
9. Attack Success Determination
Phase Evidence Contact Receipt of delivery artifact only Initial Executionwscript.exe and TEMP extraction
Persistence
Startup BAT
Payload Establishment
Injected charmap.exe and C2 connection
HVNC Establishment
Hidden desktop and screen/input APIs
Session Compromise
SaaS operations using existing cookies
Data Exfiltration
Outbound transfer of clipboard, files, or credentials
10. Investigation Playbook
-
Trigger: IOCs, AutoIt to
charmap.exe, Startup BAT, andwscript.exeextraction. - Initial Check: Preserve process tree, network connections, Startup folder, TEMP folder, and running user.
- Endpoint: Collect memory, injections, desktop objects, browser profiles, cookies, Prefetch/Amcache, and IOC hashes.
- Authentication & Cloud: Check SaaS operations, tokens, emails, files, payments, and re-authentication events at the time of the incident.
- Subsequent Actions: Investigate additional payloads, credential theft, lateral movement, and data exfiltration.
- Containment: Isolate the device, block C2, revoke sessions, change credentials, preserve evidence, and rebuild the system.
- Classification: Loader / Persistence / Payload / HVNC / Session Abuse / Exfiltration.
11. Defense and Detection Ideas
- Correlate
wscript → AutoIt → charmapexecution with Startup folder modifications. - Prioritize network connections, injections, and screen captures originating from
charmap.exe. - Use UEBA to detect browser and SaaS operations during times when the user is inactive, even if the device and IP are the same.
- Restrict WSH and AutoIt usage to authorized users only, and block C2 and unknown TCP traffic.
12. Facts / Inference / Hypothesis
- Facts: Analyzed a 5-stage process, Startup persistence, two-layer decryption, hardcoded C2, hidden desktop, and browser control APIs.
- Inference: The same device, IP, and profile weaken location-based detections in IdP systems.
-
Hypothesis: Monitoring
charmap.exeinjection, TCP connections, and screen APIs provides reliable detection independent of family-based baselines.
13. MITRE ATT&CK Mapping
- T1059.007 JavaScript/JScript (High)
- T1547.001 Registry Run Keys / Startup Folder (High)
- T1055 Process Injection (High)
- T1027 Obfuscated/Compressed Files (High)
- T1219 Remote Access Software (High)
- T1113 Screen Capture (High)
- T1115 Clipboard Data (High)
- T1539 Steal Web Session Cookie (Medium)
- T1071/T1095 Application Layer/Non-Application Layer Protocol (Medium)
14. Unknowns and Further Investigation
Initial delivery vector, complete sample hashes, C2 protocol, cookie extraction methods, full vendor feature set, infection counts, and threat actor identity.
15. Impact on SOCs
Organizations that rely on IdP systems trusting “the same device and IP” face significant blind spots. Security teams must correlate endpoint processes with SaaS activity and continuously re-evaluate the trust placed in ongoing browser sessions.
16. Summary by Target Audience
- For SOCs: Correlate the loader chain, process injections, C2 connections, hidden desktops, and SaaS operations.
- For Administrators: Restrict WSH and AutoIt, and monitor Startup folders, process injections, and unknown TCP traffic.
- For Users: Compromise can happen even when the screen looks normal. If a suspicious script runs, disconnect your device from the network and report it immediately.
답글 남기기