Russian Hackers Using Remote Access Toolkit “CTRL” for RDP Hijacking
ID: f4a16d54-231b-5651-a126-765569f1a571
STIX ID: report--f4a16d54-231b-5651-a126-765569f1a571
Feed Name: cybersecurityNews.com
A Censys ARC analysis documents a Russian-linked .NET remote access toolkit called "CTRL" that uses a weaponized LNK to launch hidden PowerShell loaders, stores payloads in Explorer-related registry keys, establishes FRP reverse tunnels for stealthy C2, patches termsrv.dll and installs RDP Wrapper to enable hidden concurrent RDP sessions, and employs a fake Windows Hello PIN prompt plus keylogging to steal credentials; persistence and escalation are achieved via scheduled tasks, registry hijacks, signed Microsoft binaries, and hidden admin accounts. Key indicators include IPs `194.33.61.36` and `109.107.168.18`, domain `hui228.ru`, registry entry `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellStateVersion1`, files `C:\Temp\keylog.txt` and `C:\ProgramData\frp\frpc.toml`, and the named pipe `ctrlPipe`.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
