typetechniquecreated2026-08-08updated2026-08-08dotnetratc2defense-evasionhost-interaction

.NET Hidden VNC (HVNC) Desktop Control

Technique: create a secondary, invisible Windows desktop (via CreateDesktopW) and run a victim's browser or application session inside it, while streaming the pixel buffer to a remote attacker over a custom TCP channel. The victim sees no window on their physical desktop; the attacker controls a "hidden" session.

Detection / Fingerprint

  • Class/method names containing Hvnc, hvncThread, isDesktopCapturing, doHvnc ^[sample 667f1f97/strings.txt:4898-5984]
  • Imports user32.dll!CreateDesktopW, SwitchDesktop, SetThreadDesktop
  • Desktop object names like DESKTOP_ENUMERATE, DESKTOP_NONE in binary strings ^[sample 667f1f97/strings.txt:4696-4763]
  • Concurrent DESKTOP_ENUMERATE and hidden window creation alongside normal GUI operation

Implementation Patterns

Typical flow:

  1. CreateDesktopW("hidden", ...) with DESKTOP_CREATEWINDOW | DESKTOP_WRITEOBJECTS rights
  2. Spawn a new thread and SetThreadDesktop to the hidden desktop
  3. Launch a browser process inside the hidden desktop
  4. Capture the desktop framebuffer via BitBlt or DXGI duplication
  5. Encode frames (JPEG/PNG) and stream over the C2 TCP socket
  6. Replay attacker input via SendInput or mouse_event into the hidden desktop

Defensive Countermeasures

  • Monitor for CreateDesktopW calls from non-system processes — extremely rare in legitimate software
  • Alert on processes that switch thread desktops (SetThreadDesktop) after launch
  • Correlation: browser process spawned by a non-browser parent with hidden window flag

Pages Where Observed

  • ratonrat 667f1f97d015 — HvncCommand, hvncThreadRunning, isDesktopCapturing in .NET RAT ^[/intel/analyses/667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9.html]