Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks
August 18, 2026
Shadow hVNC Tool Grants Covert Remote Access, Bypassing User Detection
August 18, 2026
Critical WordPress Plugin Bug Exposes 600,000 Sites to File Upload Attacks
August 18, 2026
Home/Threats/Shadow hVNC Tool Grants Covert Remote Access, Bypassing User Detection
Threats

Shadow hVNC Tool Grants Covert Remote Access, Bypassing User Detection

Key Takeaways Shadow hVNC is a sophisticated remote access tool designed for stealthy operations, creating a hidden desktop environment to evade user detection. The malware is capable of extensive...

Sarah simpson
Sarah simpson
August 18, 2026 3 Min Read
2 0

Key Takeaways

  • Shadow hVNC is a sophisticated remote access tool designed for stealthy operations, creating a hidden desktop environment to evade user detection.
  • The malware is capable of extensive data theft, including browser cookies, passwords, financial data, and session tokens, posing significant risks to sensitive accounts.
  • Attackers can leverage stolen session tokens to bypass multi-factor authentication and access accounts without needing passwords.
  • Persistence mechanisms are robust, involving disguised services, scheduled tasks, and a watchdog process to ensure continuous operation.
  • Defenders should monitor for unusual hidden desktops, browser crashes, suspicious file patterns, and unexpected network activity.

A new and highly evasive remote access tool (RAT) named Shadow hVNC has emerged, allowing attackers to gain covert control over compromised systems by operating on a hidden desktop environment. This sophisticated malware enables cybercriminals to conduct malicious activities without the victim’s knowledge, posing a severe threat to personal and corporate data, according to recent analysis.

Table Of Content

  • Key Takeaways
  • Shadow hVNC: The Invisible Hand on Your Desktop
  • Operational Modes and Evasion Techniques
  • Data Exfiltration and Persistent Access

Shadow hVNC: The Invisible Hand on Your Desktop

Unlike traditional RATs that hijack the visible user interface, Shadow hVNC operates by creating a separate, invisible Windows workspace. This hidden desktop, often named “RemoteXHidden,” allows attackers to interact with the system in real-time. They can launch browsers, command shells, PowerShell, or other applications within this isolated environment, all while the legitimate user sees their normal desktop, completely unaware of the clandestine activity. This technique significantly enhances the malware’s stealth capabilities, as documented in a detailed report on Shadow hVNC’s capabilities.

Malbear Labs, in a report shared with Cyber Security News (CSN), analyzed a 16.4 MB Go-based payload of Shadow hVNC. The researchers noted that the malware includes a hardcoded command server slot and easily readable code paths. The tool was reportedly advertised on a criminal forum in March 2026 by an account named RemoteX, indicating its availability to other malicious actors.

Beyond its core functionality, the Shadow hVNC ecosystem has expanded. Researchers identified a related loader distributed via malspam campaigns, often disguised as fake copyright notices targeting business administrators. A single click on such a deceptive document or appeal can initiate a silent account takeover, highlighting the significant threat posed by this sophisticated malware kit.

Operational Modes and Evasion Techniques

Shadow hVNC establishes a worker process attached to its hidden desktop, RemoteXHidden. From this vantage point, attackers can perform various actions, including browsing the internet, executing commands, or running scripts. The malware continuously streams screen frames from this hidden desktop to the attacker and accepts remote mouse and keyboard inputs, providing full interactive control.

A particularly dangerous feature is its “Backstage mode,” which can launch a browser using the victim’s actual profile. This allows attackers to leverage live cookies and active login sessions, effectively bypassing the need for passwords or multi-factor authentication (MFA). This capability underscores why hidden VNC attacks are more than just a privacy concern; they represent a significant risk of direct account compromise.

Should the hidden desktop creation fail, Shadow hVNC employs a more overt, but still deceptive, fallback mechanism. It can freeze the victim’s keyboard and mouse input and turn off the physical monitor, making the computer appear to be asleep. During this time, the attacker operates on the victim’s actual session, performing actions in the background while the user assumes their system is idle.

The analysis also revealed that Shadow hVNC can repeatedly terminate the victim’s Chrome browser process to seize control of the real browser profile. This allows the malware to access and manipulate sensitive browser data. Users should be vigilant for sudden browser crashes combined with any unusual background activity, as these could be critical warning signs of an ongoing attack, rather than simple software glitches.

Data Exfiltration and Persistent Access

Shadow hVNC is designed for extensive data exfiltration. It systematically collects browser cookies, saved passwords, autofill data, browser profiles, cryptocurrency wallet information, chat sessions, VPN settings, cloud service credentials, and recovery code files. The ability to inject stolen cookies into hidden browser sessions means attackers can reuse existing authentication without needing to know the victim’s password or navigate multi-factor prompts. Recent <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/317c4218-b312-4e64-9ea5-39451e174bd4/Shadow-hVNC-Gives-Attackers-Remote-Desktop-Control-Without-Moving-the-Victims-Mouse.pdf?AWSAccessKeyId=ASIA2F3EMEYE3RATSLPS&Signature=qCkjyBMvsmGzgRqT0cwo1QCBVQY%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEJD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIFNxPqctHa2eHsOj%2B9j7X%2Fyz%2BhOyee2kc0DPeZ2IlVLbAiAaqX%2BDg9xGhC5qg8wmSkFzT6CAmD87eQqooBDNeBgNYyrzBAhZEAEaDDY5OTc1MzMwOTcwNSIMn5V%2Fg4MHFZNUS1GLKtAE12sWFpfkHz0fZ2%2BJ3%2FID6ANg4N%2F4ZBfeyyqNpWVQmV%2F%2FH8wq6rNu%2BTXbdZ7IjG3JlYbB4IAMHMzlo8XSVQc%2B%2BXlTR8ugKG03Hlm7sSBLWhmaBQtDl5MPsq3HpWYzFjgCe0MjSrom8djWElvdrCwpOlNO1fZgsu%2BjMMcqWXkz4SE7GBBTtvD5ouiyC%2F2ySTVVX148TW5muoJ3hfbVFFHrqYQUONnDPO8VgD5qTVOP1uQ%2FVUNLbcAgBGbwYwVv%2B%2B7SimKpeJSdWZ61HzcWfONLeoOpxRhIMl3UCIaYgw6xi88gw5oaOXP9iQN5Xxrkz1DXtAsnNPeF5%2F4x19ZqTPuoqWuvBI1fZJSy01nz%2BVu%2F8Ded3m7WAOTJZHKllPnn%2Fi%2BBU9%2FlxyO5XCZ1JduDvzfg61V5hB9Z2OubF14Cuej8yo1yzWTbJBT0IMQBIK6kN8KZajq4AKNbSAkECL0DA%2B%2BG66yQGXh7qzJqSAMSOgtPgVuzRTNtGL1kSUHSGjuzys7LQn3ajpbhwUsEI%2FSYs%2FZZXGoHGwBknHgKrLEAq17EGVzx2O9S%2BZl1EU8Nvex76X7pWMhfFUeInvG%2By0SvG%2BI%2FI7sPPEhZ%2F

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical WordPress Plugin Bug Exposes 600,000 Sites to File Upload Attacks

Next Post

CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Best Network Sandboxing Solutions for 2026
August 18, 2026
Public Exploit Released for Critical Microsoft SCCM RCE Vulnerability CVE-2023-35887
August 18, 2026
Claude AI code enabled ransomware gang to steal LDAP passwords, backdoor VPNs
August 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us