Dev.to
7/28/2026

MedusaHVNC: Remote Control of Logged-in Browsers on Hidden Windows Desktops
Short summary
MedusaHVNC is a remote access trojan that uses JScript, AutoIt, and process injection to open logged-in browsers on a hidden Windows desktop invisible to the user. It leverages existing cookies and sessions from the victim's browser profiles, making activity appear legitimate to SaaS platforms and evading impossible-travel detections. Attackers can steal credentials, clipboard data, and screen contents while the user sees nothing on their display.
- •RAT uses hidden Windows desktops to control logged-in browser sessions via existing cookies
- •Attack chain involves JScript, AutoIt, charmap.exe injection, and ChaCha20 decryption with C2 at 51.89.204.28:4444
- •SaaS platforms see normal IP and valid sessions, making detection difficult; mitigation requires WSH/AutoIt restrictions, injection detection, and cookie protection
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



