← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 18, 2026 · 10:55via Cyber Security News

Shadow hVNC Gives Attackers Remote Desktop Control Without Moving the Victim’s Mouse

Brief

Shadow hVNC is a remote access tool built to operate where victims cannot see it.

Instead of taking over the visible desktop, it can create a separate Windows workspace and give criminals a live view of activity inside it.

The malware steals browser cookies, saved passwords, financial data, and session tokens, then uses them to access accounts already signed in on the compromised computer.

That creates a serious risk for banking, cloud services, and corporate applications.

Analysts at Malbear Labs identified the latest Shadow hVNC build as a 16.4 MB Go-based payload with a hardcoded command server slot and readable code paths.

Malbear Labs said in a report shared with Cyber Security News (CSN) An account using the name RemoteX advertised the stealer on a criminal forum in March 2026. The campaign ecosystem has expanded beyond the core implant.

Read more on Cyber Security News