← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 8, 2026 · 10:24via ANY.RUN Blog

HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures

Brief

Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher & threat hunter. You can find Moises on LinkedIn and X .

Fake tax documents are being used to target organizations across LATAM, delivering a custom HVNC backdoor built for stealthy, persistent access. Once installed, the malware can give attackers hidden remote control, steal browser data, monitor keystrokes, and survive system reboots.

The attack chain combines trusted business lures, anti-analysis techniques, and infrastructure designed to keep access hidden. For security leaders, the risk goes beyond a single compromised endpoint: persistent access can expose credentials, sensitive data, and business systems while giving attackers more time to move deeper into the environment.

Read more on ANY.RUN Blog