Shadow hVNC Gives Attackers Remote Desktop Control Without Moving the Victim’s Mouse

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Shadow hVNC is a remote access tool built to operate where victims cannot see it.

Instead of taking over the visible desktop, it can create a separate Windows workspace and give criminals a live view of activity inside it.

The malware steals browser cookies, saved passwords, financial data, and session tokens, then uses them to access accounts already signed in on the compromised computer.

That creates a serious risk for banking, cloud services, and corporate applications.

Analysts at Malbear Labs identified the latest Shadow hVNC build as a 16.4 MB Go-based payload with a hardcoded command server slot and readable code paths.

Malbear Labs said in a report shared with Cyber Security News (CSN) An account using the name RemoteX advertised the stealer on a criminal forum in March 2026.

Shadow HVNC advertisement poster (Source – Medium)

The researchers linked a related loader to malspam using fake copyright notices aimed at business-page administrators. A single click can turn a document or appeal notice into an entry point for quiet account theft.

Shadow hVNC Gives Attackers Remote Desktop Control

Shadow hVNC creates a second Windows desktop called RemoteXHidden and attaches a worker process to it.

An operator can launch a browser, command shell, PowerShell, or another program in that hidden area while the victim sees their desktop.

The malware streams screen frames and accepts remote mouse clicks and keystrokes.

Its newer Backstage mode can open a browser against the victim’s real profile, allowing the operator to use live cookies and active logins.

That is why hidden VNC attack risks are more than a privacy concern: a valid session may remove the need to know a password.

If hidden-desktop creation fails, Shadow hVNC falls back to a noisier method. It can freeze keyboard and mouse input and turn off the physical monitor while the attacker works on the victim’s real session.

LSASS dumping with lss.exe (Source – Medium)

The computer may appear asleep, even though activity continues in the background.

Sudden browser crashes alongside unfamiliar background activity should be treated as a warning sign, not a routine software failure.

Cookie Theft and Persistent Access

The tool collects cookies, passwords, autofill details, browser profile data, cryptocurrency wallets, chat sessions, VPN settings, cloud credentials, and recovery-code files.

It can inject stolen cookies into a hidden browser session, enabling account reuse without prompting for a password or second factor. Recent stolen cookie abuse reports show why active browser sessions remain targets for criminals.

Shadow hVNC also includes an embedded utility named lss.exe that can capture Windows Local Security Authority process memory when it has administrator rights.

The resulting data may contain credentials useful for moving deeper into an organization, a risk also illustrated by cached credential theft techniques.

Backstage Mode (Source – Medium)

Persistence is a major concern. The malware can copy itself into local application-data folders, register a service disguised as “mouse driver service,” create Run entries and scheduled tasks, and deploy a watchdog called WmiPrvSE.exe to restore the payload after it is stopped.

It also attempts to add security-tool exclusions when elevated.

Teams should also investigate unexpected scheduled tasks, new Run values, security exclusion changes, and processes that kill browsers they did not start.

Organizations should isolate suspected devices, preserve relevant logs, reset exposed sessions and credentials from a system, and review administrator access.

Browser cookies can bypass the convenience of multi-factor prompts, so response teams should revoke sessions, not merely change passwords. Guidance on session cookie takeover prevention explains why that distinction matters.

Indicators of compromise (IoCs):-

Type Indicator Description
IP address and URL hxxp://212.162.150[.]121/v1/verify Shadow hVNC panel license-verification endpoint observed in the analysis
MD5 hash 85c5a390f17891eee01d5fd10f20a98d Embedded lss.exe utility used to create an LSASS memory dump
MD5 hash 1d04536714bb22a3e909525a7dd627f0 Embedded chrome_injector.exe / ChromElevator component
MD5 hash 9675c957a5fded266939e314abff2078 Embedded watchdog executable used to help restore the payload
File name lss.exe Temporary credential-dumping utility written by the malware before execution
File name lss.dmp LSASS memory dump created by lss.exe
File name WmiPrvSE.exe Shadow hVNC watchdog filename dropped to the user’s local application-data directory
File path %LOCALAPPDATA%MicrosoftWindowsWmiPrvSE.exe Observed watchdog drop location
File pattern *.rxcopy Browser database copies, including Login Data.rxcopyCookies.rxcopy, and cookies.sqlite.rxcopy
File path %LOCALAPPDATA%RemoteXProfiles Profile-cloning directory used by the malware, including .staging folders
Mutex GlobalRemoteX_<client ID> Named mutex created to prevent multiple Shadow hVNC instances from running
Hidden desktop RemoteXHidden Invisible Windows desktop created for hidden attacker activity
Hidden desktop RemoteXBackstage Desktop name associated with Backstage browser sessions
Service winSvc Windows service name created for persistence
Service display name mouse driver service Masqueraded display name used by the persistence service
Registry value RemoteX Run-key value used for user and, when elevated, system-wide persistence
Scheduled task MicrosoftWindowsManagementClient Logon-triggered scheduled task created by the payload
Scheduled task MicrosoftWindowsManagementClientBoot Startup-triggered scheduled task created by the payload
Scheduled task MicrosoftWindowsManagementClientPerf Scheduled task configured to relaunch the payload every five minutes
Network pattern ws://<C2>/ws/client?id=<client ID> Primary command-and-control WebSocket path
Network pattern /ws/backstage-src?target=<browser>&generation=<n> WebSocket endpoint used for hidden Backstage browser sessions
Network pattern /api/upload-data Endpoint used to exfiltrate collected data archives
Network pattern /api/upload-creds Endpoint used to upload compressed LSASS dump data
Network pattern /api/keylog Endpoint used for keylogger data uploads
Network pattern /api/domain-screenshot Endpoint used to upload banking-session screen captures
URL hxxp://ciscobinary.openh264[.]org/openh264-2.4.1-win64.dll.bz2 OpenH264 download URL contacted when the malware enables H.264 streaming

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world