You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
purehvnc
About this tag
The purehvnc tag on WindowsForum.com covers discussions about PureHVNC, a remote access trojan (RAT) often delivered through trojanized installers of legitimate remote administration tools like ConnectWise ScreenConnect. Threat actors use PureHVNC to establish persistent, stealthy access to compromised Windows systems, enabling data theft, keylogging, and lateral movement within networks. Topics include detection, analysis of infection chains, and mitigation strategies for enterprise IT and security professionals. The tag focuses on the abuse of remote monitoring and management (RMM) software as an initial access vector, with PureHVNC serving as a secondary payload for maintaining long-term control over affected endpoints.
Since March 2025, threat actors have increasingly weaponized ConnectWise ScreenConnect installers — using trojanized, stripped-down ClickOnce runners and other delivery tricks to convert a trusted remote administration tool into a stealthy initial-access vector that drops multiple RATs and...