MedusaHVNC malware hijacks live browser sessions on Windows

Security researchers at BlackFog have discovered a new malware family called MedusaHVNC that hijacks active browser sessions on Windows devices. By using a hidden virtual network computing module, attackers can operate within legitimate user sessions to bypass traditional credential-based security.
Why it matters
This represents a sophisticated evolution in session theft, moving beyond simple password stealing to active, real-time exploitation of authenticated browser environments.
BlackFog has identified a malware family called MedusaHVNC that can hijack live browser sessions on Windows devices, giving attackers access to active logged-in sessions through a hidden desktop.
Sold as a malware-as-a-service offering, it includes a hidden virtual network computing module that runs a browser session out of the user's sight. Because the browser runs on the victim's own machine, it can use existing profiles, cookies and session data, allowing an attacker to operate within sessions that already appear legitimate.
The finding points to a form of session theft that differs from simple credential harvesting. Rather than relying only on stolen usernames and passwords, the software appears designed to let operators work directly inside a victim's current browser environment.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in