MedusaHVNC Trojan Enables Invisible Remote Control of PCs

MedusaHVNC Trojan Enables Invisible Remote Control of PCs

First seen 27 Jul 2026, 19:52 UTC CybersecuritynewsSecurityaffairs.Co 86% similarity 66.5

Article Content

Browse articles
ThreatCluster

The MedusaHVNC remote access Trojan allows attackers to create hidden virtual desktops on victims' computers, enabling them to access browsers and steal sensitive data without detection. This malware is marketed as a service through a dedicated website and Telegram channel, targeting users who may not be aware of its capabilities. It exploits legitimate Windows features to evade detection, making it a significant threat to individuals and organizations alike. The Trojan can access real browser profiles, cookies, and logged-in sessions, posing a risk to personal and corporate data. Users of Windows systems are particularly vulnerable, as the malware leverages hidden desktop functionalities. The current status indicates ongoing sales and distribution of MedusaHVNC in the cybercriminal underground.

Key Points: • MedusaHVNC allows remote control of PCs via hidden desktops, stealing sensitive data. • The Trojan is marketed as malware-as-a-service, increasing its accessibility to attackers. • Windows users are particularly at risk due to the exploitation of legitimate system features.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
MedusaHVNC Trojan discovered
Researchers identified MedusaHVNC, a RAT that creates hidden desktops to control browsers and steal data.
Cybersecuritynews
2026-07-27
Malware sold as service
MedusaHVNC is being sold through a dedicated website and Telegram channel, making it widely accessible.
Securityaffairs.Co
Recent
Exploitation of hidden desktop feature
The Trojan exploits legitimate Windows features, allowing it to evade detection and control user environments.
Securityaffairs.Co

Community

Browse all →

Tracked Entities in This Story