MedusaHVNC hijacks browser sessions, bypasses MFA protections

In new research, BlackFog’s Darren Williams details how MedusaHVNC gives attackers covert access to live, logged-in browser sessions by opening a legitimate browser on a hidden Windows desktop. Because the activity occurs on the victim’s own device using its existing profile, cookies and session state, the malware can exploit authenticated accounts while remaining invisible to the user.

Jacob Krell, Senior Director, Secure AI Solutions & Cybersecurity, Suzu Labs had this to say:

“MedusaHVNC doesn’t need to steal credentials. It launches a real browser inside a hidden Windows desktop using the victim’s existing profile, so the attacker’s session arrives pre-loaded with every cookie, saved password, and active authentication token the victim already has. Multi-factor authentication (MFA), passkeys, hardware tokens, all of them authenticated that browser before the attacker showed up.

“Most organizations are investing in authentication hardening right now, phishing-resistant MFA, passkey rollouts, conditional access. All of it protects the login. MedusaHVNC operates entirely after the login, where the attacker’s session looks identical to the victim’s, same machine, same IP, same browser fingerprint, same cookies. Token binding and continuous session validation are what cover that gap.

“Hidden Virtual Network Computing (HVNC) used to be one of the hardest malware features to build. MalwareTech documented in 2015 that it essentially required writing your own window manager. MedusaHVNC now sells that capability through a dedicated website and Telegram channel, with an operator panel where you pick a browser from a dropdown and adjust the frame rate. That’s the industrialization of cybercrime compressed into a single feature’s history, a capability that once required deep Windows internals expertise is now a product with customer support.

“The infection chain is a living-off-the-land sequence, wscript.exe to AutoIt to charmap.exe, every binary signed and trusted until the final payload drops. In my experience, living-off-the-land chains evade detection better than custom malware because endpoint detection and response (EDR) flags unknown executables, not trusted ones behaving slightly wrong. Application allowlisting breaks this chain at the first stage. If a workstation doesn’t need wscript.exe or AutoIt, disable them. ‘Ships with Windows’ and ‘needed on this host’ are different questions, and attack surface reduction is how you stop living-off-the-land chains before they reach the payload.”

John Strand, Owner, Black Hills Information Security, Inc. follows with this:

“Browser-based persistence is becoming one of the next major frontiers in cybersecurity. For years, we’ve focused on securing the endpoint, but once malicious activity moves into the browser, visibility becomes much more difficult. Many security vendors intentionally take a hands-off approach to browser activity because of legitimate privacy concerns. A lot of organizations aren’t fully decrypting TLS traffic, let alone inspecting exactly what’s happening inside a user’s browser.

“The reality is that the browser has become the new endpoint. Nearly every business application and cloud service runs through it. Browser-focused attack frameworks have existed for years, but this latest campaign shows they’re becoming more sophisticated. Attackers are shifting away from techniques that target only the operating system and are investing in methods that are harder to detect and much more resilient.”

Organizations need to look at their security in an holistic way. Because only focusing on one area will guarantee that you get pwned.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading