Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels
ID: afca1ab6-7136-5c8e-b76a-949df38a8448
STIX ID: report--afca1ab6-7136-5c8e-b76a-949df38a8448
Feed Name: The Hacker News
Researchers uncovered a Russian-origin remote access toolkit called CTRL distributed via malicious Windows LNK files that impersonate private key folders; the toolkit is a .NET-based RAT providing credential harvesting (a Windows Hello PIN phishing UI), keylogging, RDP session hijacking, and reverse tunneling via FRP. The attack chain uses a hidden PowerShell stager that tests connectivity to hui228.ru:7000, downloads and launches ctrl.exe (a dual-mode management platform communicating over a named pipe), and drops FRPWrapper.exe and RDPWrapper.exe to establish FRP tunnels and enable concurrent RDP sessions — an architecture designed to minimize traditional network C2 artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
