View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA says ransomware gangs are exploiting a Windows Task Host flaw

๐Ÿšจ ACTIVE EXPLOITATION

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Shadow hVNC Gives Attackers Invisible Control of a Second Windows Desktop
    Shadow hVNC gives attackers invisible control of a second Windows desktop.
    • Windows users and enterprise environments are targeted by the Shadow hVNC malware-as-a-service toolkit.
    • Version 5.5 steals browser credentials, cookies, session tokens, financial data, crypto-wallet artifacts, and cloud credentials.
    • The malware creates a hidden Win32 desktop named RemoteXHidden for attacker-controlled browsers, shells, and payloads.
    • Backstage Mode hijacks Chrome profiles and replays cookies through Chrome DevTools Protocol.
    • Observed indicators include RemoteXHidden, RemoteXBackstage, MD5 1d04536714bb22a3e909525a7dd627f0, and IPs 195.3.221[.]225 and 62.60.226[.]253.
      ๐Ÿ“„ Source: malbearlabs.com ยท ๐Ÿ“Ž Coverage: gbhackers.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check