HVNC Backdoor Uses Fake Tax and DocuSign Lures to Target Latin American Organizations

Summary
Researchers detail a phishing campaign targeting Latin American financial organizations with fake DocuSign and tax-document lures that install a custom HVNC backdoor for hidden remote access, data theft, and persistence.
Key points
- The campaign targets banking and financial services in Latin America using fake DocuSign notices, Brazilian NFe tax documents, banking lures, and related ClickFix-style delivery.
- The infection chain uses a spoofed page to deliver a ZIP containing a disguised LNK; hidden PowerShell downloads an NSIS installer that carries the backdoor.
- The unsigned payload masquerades as Windows Update Assistant and provides hidden-desktop remote control, screen capture, keystroke monitoring, and Firefox cookie, history, and permission theft.
- It checks for more than 20 AV/EDR processes, establishes Startup-folder persistence, and reconnects to raw-TCP command-and-control; observed ports vary by build.
- The C2 handshake exposes protocol markers and victim system details, while researchers link infrastructure to other financial-themed lures. Attribution to Silver Fox/Winos4.0-adjacent activity remains unconfirmed.
- The analysis recommends hunting for disguised LNK-to-PowerShell execution, unusual Startup-folder shortcuts, HVNC behavior, and protocol strings rather than relying only on rotating hashes or infrastructure.
Article Details
- Attack Vectors
- Fake DocuSign document notices and Brazilian NFe tax-document lures lead visitors to a phishing page that checks for automation and user interaction before returning a base64-encoded ZIP.
- The ZIP contains a tax-receipt-themed Windows shortcut. Opening it runs hidden PowerShell that downloads and starts an NSIS installer from a staging host.
- The installer bundles the unsigned backdoor with legitimate, unmodified DLLs. The backdoor uses a hidden desktop for remote control, communicates with a C2 server over raw TCP, and creates Startup-folder persistence.
- Related activity used banking-themed phishing and ClickFix-style prompts; the source does not establish that every delivery method was used in the same infection.
- Defensive Notes
- Flag hidden PowerShell launched from shortcuts, particularly commands combining Invoke-WebRequest and Start-Process.
- Investigate unsigned Windows Update-themed executables outside legitimate Windows directories, and unusual Startup-folder shortcuts pointing to executables under %APPDATA%.
- Hunt for hidden-desktop creation combined with screen capture and simulated input. Monitor for the HVNC- handshake, VERSION:1.2.0.4.71, and the nfe_valid_access_key_2026_secure delivery token; ports and payload hashes vary between builds.
- Analyze unexpected signing requests, tax-document downloads, and suspicious files in isolation. After compromise, check persistence, stop malicious processes and C2 access, and review potentially exposed credentials and browser sessions.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | aapj[.]digital | Banco do Brasil corporate-banking phishing clone; the source assesses its cluster link at medium confidence. |
| DOMAIN | gerenciadorcaixa[.]digital | Caixa Econômica Federal corporate-banking phishing clone; the source assesses its cluster link at medium-high confidence. |
| DOMAIN | receitafederal[.]digital | NFe-themed delivery-lure domain. |
| IPV4 | 40[.]124[.]169[.]27 | Azure-hosted stage-two payload staging IP identified in the network indicators. |
| IPV4 | 5[.]230[.]249[.]49 | Decoded live HVNC C2 IP; the source also observed it serving stage-two payloads. C2 ports varied between builds. |
| IPV4 | 5[.]230[.]54[.]41 | Secondary delivery and co-hosted phishing IP identified in the network indicators. |
| SHA256 | 1f2d41c4aa5db0bc33ebf7b66d72943a817d7ce6cbe880502a9403823633093f | Hash listed for an unmodified vcruntime140_1.dll cover file relocated with the backdoor; the source says the DLL is not trojanized. |
| SHA256 | 25db85830d86cafbb93a660242f8b4017273cc4612e94dd7a8af29c948651bbe | Hash of the AppUpdateHelper.lnk persistence shortcut. |
| SHA256 | 54716f0738af891f283d213b5c8d11b25896bb8ee3097d301eae718560cf974e | Hash listed for an unmodified concrt140.dll cover file relocated with the backdoor; the source says the DLL is not trojanized. |
| SHA256 | 5fbfc7929858c3c3d79637db857525695db3c0f41b9bf2a7b964c26b7226bde3 | Hash of the statically analyzed UpdateAssistant.exe backdoor build. |
| SHA256 | 7c26614e1d733892c2deac7e245ce115504b1d80592dd0a01b08e3e5a55f89ca | Hash listed for an unmodified msvcp140.dll cover file relocated with the backdoor; the source says the DLL is not trojanized. |
| SHA256 | 97f35ba586fc121590c867b4d6707777fbeca2ace5ad077807ec806540bb47cd | Hash of the second NFe-themed ZIP dropper build. |
| SHA256 | d1f4225df2cd877dbf130d5668a021dce3f94118455ff5ec952061c30afc9ce7 | Hash listed for an unmodified vcruntime140.dll cover file relocated with the backdoor; the source says the DLL is not trojanized. |
| SHA256 | debf48e690abd4288e5f76fa7e9f98a9fb3411171eba82906ef0d2bf1ef2dd6d | Hash of the dynamically captured backdoor build, also copied as AppUpdateHelper.exe for persistence. |
| SHA256 | e4d637f884f5babea6525266e1cb6ab332a16a446d6084dd51b4222540c1f16c | Hash of the first NFe-themed ZIP dropper build. |
| URL | hxxp[:]//5[.]230[.]249[.]49/dl[.]php?f=cresol[.]exe&k=chave_tecl_cresol | Specific stage-two payload delivery URL for a banking-themed lure variant. |
| URL | hxxp[:]//5[.]230[.]249[.]49/dl[.]php?f=payed[.]exe | Specific stage-two payload delivery URL for a generic-themed lure variant. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe page returns a base64-encoded ZIP, while the backdoor stores its C2 host as single-byte-XOR-encoded bytes.T1036.005 · Match Legitimate Resource Name or LocationThe shortcut is disguised as a tax receipt, and the unsigned payload identifies itself as Microsoft's Windows Update Assistant.T1056.001 · KeyloggingKeyboard-state API imports support the reported keystroke-monitoring capability, although the active polling loop was not fully traced.T1059.001 · PowerShellThe .lnk runs a hidden PowerShell one-liner with execution-policy bypass to download and start the next stage.T1095 · Non-Application Layer ProtocolThe article describes a custom raw-TCP HVNC C2 protocol rather than HTTP or WebSocket.T1105 · Ingress Tool TransferPowerShell Invoke-WebRequest retrieves the NSIS installer from the payload staging host.T1113 · Screen CaptureHidden-desktop remote-control functionality uses screen-capture APIs and an OpenCV-backed frame queue.T1204.002 · Malicious FileThe infection chain relies on a victim opening the disguised .lnk file from the downloaded ZIP.T1217 · Browser Information DiscoveryThe payload contains hardcoded references to Firefox history and permissions databases, places.sqlite and permissions.sqlite.T1518.001 · Security Software DiscoveryThe backdoor checks more than 20 hardcoded AV/EDR process names and reports the antivirus-discovery result during C2 check-in.T1539 · Steal Web Session CookieHardcoded targeting of Firefox cookies.sqlite supports the reported browser-cookie theft capability.T1547.001 · Registry Run Keys / Startup FolderThe backdoor copies itself as AppUpdateHelper.exe and places a shortcut to that copy in the current user's Startup folder; this was dynamically confirmed.T1566.002 · Spearphishing LinkFake DocuSign and NFe document notices direct targets to the payload-delivery page.T1571 · Non-Standard PortThe backdoor uses raw-TCP C2 on port 27015 in one build and was observed connecting on port 27017 in another.T1592 · Gather Victim Host InformationBefore releasing the ZIP, the lure page reports visitor browser, operating-system, timezone, and screen-size details to its server.
Threat Actors
Vendors
ANY.RUNPhishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN's Latest UpdatesGHOSTnet GmbHand a browser-redirection command – all communicating over TCP/27015 to infrastructure hosted with GHOSTnet GmbH (Frankfurt, DE).MicrosoftStage 4 – Payload: a 64-bit backdoor (masquerading as “Windows Update Assistant” / Microsoft Corporation in its version metadata, while unsigned) implementing AV/EDR discovery, a hidden virtual desktop for remote
Products
FirefoxCredential and session theft: The malware monitors keystrokes and targets Firefox cookies, browsing history, and permissions, putting account access at risk.Microsoft AzurePowerShellStage 2 – Dropper: a Windows .lnk shortcut disguised as a tax-document receipt, whose target is a hidden PowerShell one-liner that downloads and executes a second-stage binary.WindowsStage 2 – Dropper: a Windows .lnk shortcut disguised as a tax-document receipt, whose target is a hidden PowerShell one-liner that downloads and executes a second-stage binary.
Tools
ANY.RUN Interactive SandboxANY.RUN Threat Intelligence LookupDetect It EasyStatic analysis in Detect It Easy immediately flags the giveaways: UnsignedMicrosoft, repeated XorInLoop patterns, and YARA hits for KeyloggerApi and BrowserStealer.IDA ProReversing the network-setup routine in IDA Pro shows why.ShodanQuerying Shodan for the staging IP (an Azure VM used only to host the second-stage download) showed an exposed RPC endpoint mapper leaking that exact NetBIOS name, confirming the builder machine and the delivery hostSuricataStructural protocol markers suitable for network-content (Suricata) detection independent of C2 IP/port rotationYARAStatic analysis in Detect It Easy immediately flags the giveaways: UnsignedMicrosoft, repeated XorInLoop patterns, and YARA hits for KeyloggerApi and BrowserStealer.