.NET Hidden VNC (HVNC) Desktop Control
Technique: create a secondary, invisible Windows desktop (via CreateDesktopW) and run a victim's browser or application session inside it, while streaming the pixel buffer to a remote attacker over a custom TCP channel. The victim sees no window on their physical desktop; the attacker controls a "hidden" session.
Detection / Fingerprint
- Class/method names containing
Hvnc,hvncThread,isDesktopCapturing,doHvnc^[sample 667f1f97/strings.txt:4898-5984] - Imports
user32.dll!CreateDesktopW,SwitchDesktop,SetThreadDesktop - Desktop object names like
DESKTOP_ENUMERATE,DESKTOP_NONEin binary strings ^[sample 667f1f97/strings.txt:4696-4763] - Concurrent
DESKTOP_ENUMERATEand hidden window creation alongside normal GUI operation
Implementation Patterns
Typical flow:
CreateDesktopW("hidden", ...)withDESKTOP_CREATEWINDOW | DESKTOP_WRITEOBJECTSrights- Spawn a new thread and
SetThreadDesktopto the hidden desktop - Launch a browser process inside the hidden desktop
- Capture the desktop framebuffer via
BitBltor DXGI duplication - Encode frames (JPEG/PNG) and stream over the C2 TCP socket
- Replay attacker input via
SendInputormouse_eventinto the hidden desktop
Defensive Countermeasures
- Monitor for
CreateDesktopWcalls from non-system processes — extremely rare in legitimate software - Alert on processes that switch thread desktops (
SetThreadDesktop) after launch - Correlation: browser process spawned by a non-browser parent with hidden window flag
Pages Where Observed
- ratonrat
667f1f97d015—HvncCommand,hvncThreadRunning,isDesktopCapturingin .NET RAT ^[/intel/analyses/667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9.html]