HVNC Backdoor Uses Fake Tax and DocuSign Lures to Target Latin American Organizations

· Original article ↗

Summary

Researchers detail a phishing campaign targeting Latin American financial organizations with fake DocuSign and tax-document lures that install a custom HVNC backdoor for hidden remote access, data theft, and persistence.

Key points

  • The campaign targets banking and financial services in Latin America using fake DocuSign notices, Brazilian NFe tax documents, banking lures, and related ClickFix-style delivery.
  • The infection chain uses a spoofed page to deliver a ZIP containing a disguised LNK; hidden PowerShell downloads an NSIS installer that carries the backdoor.
  • The unsigned payload masquerades as Windows Update Assistant and provides hidden-desktop remote control, screen capture, keystroke monitoring, and Firefox cookie, history, and permission theft.
  • It checks for more than 20 AV/EDR processes, establishes Startup-folder persistence, and reconnects to raw-TCP command-and-control; observed ports vary by build.
  • The C2 handshake exposes protocol markers and victim system details, while researchers link infrastructure to other financial-themed lures. Attribution to Silver Fox/Winos4.0-adjacent activity remains unconfirmed.
  • The analysis recommends hunting for disguised LNK-to-PowerShell execution, unusual Startup-folder shortcuts, HVNC behavior, and protocol strings rather than relying only on rotating hashes or infrastructure.

Article Details

Attack Vectors
  • Fake DocuSign document notices and Brazilian NFe tax-document lures lead visitors to a phishing page that checks for automation and user interaction before returning a base64-encoded ZIP.
  • The ZIP contains a tax-receipt-themed Windows shortcut. Opening it runs hidden PowerShell that downloads and starts an NSIS installer from a staging host.
  • The installer bundles the unsigned backdoor with legitimate, unmodified DLLs. The backdoor uses a hidden desktop for remote control, communicates with a C2 server over raw TCP, and creates Startup-folder persistence.
  • Related activity used banking-themed phishing and ClickFix-style prompts; the source does not establish that every delivery method was used in the same infection.
Defensive Notes
  • Flag hidden PowerShell launched from shortcuts, particularly commands combining Invoke-WebRequest and Start-Process.
  • Investigate unsigned Windows Update-themed executables outside legitimate Windows directories, and unusual Startup-folder shortcuts pointing to executables under %APPDATA%.
  • Hunt for hidden-desktop creation combined with screen capture and simulated input. Monitor for the HVNC- handshake, VERSION:1.2.0.4.71, and the nfe_valid_access_key_2026_secure delivery token; ports and payload hashes vary between builds.
  • Analyze unexpected signing requests, tax-document downloads, and suspicious files in isolation. After compromise, check persistence, stop malicious processes and C2 access, and review potentially exposed credentials and browser sessions.

Indicators of compromise

TypeIndicatorContext
DOMAINaapj[.]digitalBanco do Brasil corporate-banking phishing clone; the source assesses its cluster link at medium confidence.
DOMAINgerenciadorcaixa[.]digitalCaixa Econômica Federal corporate-banking phishing clone; the source assesses its cluster link at medium-high confidence.
DOMAINreceitafederal[.]digitalNFe-themed delivery-lure domain.
IPV440[.]124[.]169[.]27Azure-hosted stage-two payload staging IP identified in the network indicators.
IPV45[.]230[.]249[.]49Decoded live HVNC C2 IP; the source also observed it serving stage-two payloads. C2 ports varied between builds.
IPV45[.]230[.]54[.]41Secondary delivery and co-hosted phishing IP identified in the network indicators.
SHA2561f2d41c4aa5db0bc33ebf7b66d72943a817d7ce6cbe880502a9403823633093fHash listed for an unmodified vcruntime140_1.dll cover file relocated with the backdoor; the source says the DLL is not trojanized.
SHA25625db85830d86cafbb93a660242f8b4017273cc4612e94dd7a8af29c948651bbeHash of the AppUpdateHelper.lnk persistence shortcut.
SHA25654716f0738af891f283d213b5c8d11b25896bb8ee3097d301eae718560cf974eHash listed for an unmodified concrt140.dll cover file relocated with the backdoor; the source says the DLL is not trojanized.
SHA2565fbfc7929858c3c3d79637db857525695db3c0f41b9bf2a7b964c26b7226bde3Hash of the statically analyzed UpdateAssistant.exe backdoor build.
SHA2567c26614e1d733892c2deac7e245ce115504b1d80592dd0a01b08e3e5a55f89caHash listed for an unmodified msvcp140.dll cover file relocated with the backdoor; the source says the DLL is not trojanized.
SHA25697f35ba586fc121590c867b4d6707777fbeca2ace5ad077807ec806540bb47cdHash of the second NFe-themed ZIP dropper build.
SHA256d1f4225df2cd877dbf130d5668a021dce3f94118455ff5ec952061c30afc9ce7Hash listed for an unmodified vcruntime140.dll cover file relocated with the backdoor; the source says the DLL is not trojanized.
SHA256debf48e690abd4288e5f76fa7e9f98a9fb3411171eba82906ef0d2bf1ef2dd6dHash of the dynamically captured backdoor build, also copied as AppUpdateHelper.exe for persistence.
SHA256e4d637f884f5babea6525266e1cb6ab332a16a446d6084dd51b4222540c1f16cHash of the first NFe-themed ZIP dropper build.
URLhxxp[:]//5[.]230[.]249[.]49/dl[.]php?f=cresol[.]exe&k=chave_tecl_cresolSpecific stage-two payload delivery URL for a banking-themed lure variant.
URLhxxp[:]//5[.]230[.]249[.]49/dl[.]php?f=payed[.]exeSpecific stage-two payload delivery URL for a generic-themed lure variant.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe page returns a base64-encoded ZIP, while the backdoor stores its C2 host as single-byte-XOR-encoded bytes.T1036.005 · Match Legitimate Resource Name or LocationThe shortcut is disguised as a tax receipt, and the unsigned payload identifies itself as Microsoft's Windows Update Assistant.T1056.001 · KeyloggingKeyboard-state API imports support the reported keystroke-monitoring capability, although the active polling loop was not fully traced.T1059.001 · PowerShellThe .lnk runs a hidden PowerShell one-liner with execution-policy bypass to download and start the next stage.T1095 · Non-Application Layer ProtocolThe article describes a custom raw-TCP HVNC C2 protocol rather than HTTP or WebSocket.T1105 · Ingress Tool TransferPowerShell Invoke-WebRequest retrieves the NSIS installer from the payload staging host.T1113 · Screen CaptureHidden-desktop remote-control functionality uses screen-capture APIs and an OpenCV-backed frame queue.T1204.002 · Malicious FileThe infection chain relies on a victim opening the disguised .lnk file from the downloaded ZIP.T1217 · Browser Information DiscoveryThe payload contains hardcoded references to Firefox history and permissions databases, places.sqlite and permissions.sqlite.T1518.001 · Security Software DiscoveryThe backdoor checks more than 20 hardcoded AV/EDR process names and reports the antivirus-discovery result during C2 check-in.T1539 · Steal Web Session CookieHardcoded targeting of Firefox cookies.sqlite supports the reported browser-cookie theft capability.T1547.001 · Registry Run Keys / Startup FolderThe backdoor copies itself as AppUpdateHelper.exe and places a shortcut to that copy in the current user's Startup folder; this was dynamically confirmed.T1566.002 · Spearphishing LinkFake DocuSign and NFe document notices direct targets to the payload-delivery page.T1571 · Non-Standard PortThe backdoor uses raw-TCP C2 on port 27015 in one build and was observed connecting on port 27017 in another.T1592 · Gather Victim Host InformationBefore releasing the ZIP, the lure page reports visitor browser, operating-system, timezone, and screen-size details to its server.

Threat Actors

Vendors

Products

Tools

Countries

Industries

Related Articles