logo

Russian Hackers Deploy “CTRL” for RDP Hijacking

ID: 12f0ffaf-c4d3-5cc0-8cd3-68728a3bc27d

STIX ID: report--12f0ffaf-c4d3-5cc0-8cd3-68728a3bc27d

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Executive Summary: The report documents a previously undocumented, privately developed .NET remote access toolkit named "CTRL" used by Russian-linked attackers to stealthily hijack and shadow RDP sessions over FRP reverse tunnels. Delivery is via a weaponized Windows LNK that loads an in-memory stager, persists components in the registry and scheduled tasks, uses a fodhelper UAC bypass and termsrv.dll/ RDP Wrapper techniques, and provides operators with named-pipe control, keylogging, phishing windows, and exfiltration capabilities; observed infrastructure includes hui228.ru and FRP relays at 194.33.61.36 and 109.107.168.18 (port 7000).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.