logo

Under CTRL: Dissecting a Previously Undocumented Russian .Net Access Framework

ID: beb21ffb-b8cf-52d6-bf9f-5d29f8670b87

STIX ID: report--beb21ffb-b8cf-52d6-bf9f-5d29f8670b87

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2026-03-27

Date Updated: 2026-04-27

...
...

CTRL is a previously undocumented Russian‑language .NET remote access toolkit delivered via a socially engineered LNK dropper that executes a multi-layer PowerShell/.NET stager in memory. The toolkit provides validated Windows Hello credential harvesting, persistent keylogging, automated RDP enablement and hijacking, and FRP-based reverse tunneling for operator access; Censys observed active infrastructure (hui228.ru and IPs 194.33.61.36, 109.107.168.18) and enumerated host and network indicators for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.