logo

Russian Hackers Using Remote Access Toolkit “CTRL” for  RDP Hijacking

ID: f4a16d54-231b-5651-a126-765569f1a571

STIX ID: report--f4a16d54-231b-5651-a126-765569f1a571

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-01

Date Updated: 2026-04-21

Author: Abinaya

...
...

A Censys ARC analysis documents a Russian-linked .NET remote access toolkit called "CTRL" that uses a weaponized LNK to launch hidden PowerShell loaders, stores payloads in Explorer-related registry keys, establishes FRP reverse tunnels for stealthy C2, patches termsrv.dll and installs RDP Wrapper to enable hidden concurrent RDP sessions, and employs a fake Windows Hello PIN prompt plus keylogging to steal credentials; persistence and escalation are achieved via scheduled tasks, registry hijacks, signed Microsoft binaries, and hidden admin accounts. Key indicators include IPs `194.33.61.36` and `109.107.168.18`, domain `hui228.ru`, registry entry `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellStateVersion1`, files `C:\Temp\keylog.txt` and `C:\ProgramData\frp\frpc.toml`, and the named pipe `ctrlPipe`.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.