logo

Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels

ID: afca1ab6-7136-5c8e-b76a-949df38a8448

STIX ID: report--afca1ab6-7136-5c8e-b76a-949df38a8448

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers uncovered a Russian-origin remote access toolkit called CTRL distributed via malicious Windows LNK files that impersonate private key folders; the toolkit is a .NET-based RAT providing credential harvesting (a Windows Hello PIN phishing UI), keylogging, RDP session hijacking, and reverse tunneling via FRP. The attack chain uses a hidden PowerShell stager that tests connectivity to hui228.ru:7000, downloads and launches ctrl.exe (a dual-mode management platform communicating over a named pipe), and drops FRPWrapper.exe and RDPWrapper.exe to establish FRP tunnels and enable concurrent RDP sessions — an architecture designed to minimize traditional network C2 artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.