Cybersecurity researchers have discovered an advanced CTRL toolkit of Russian origin, distributed via malicious Windows LNK files disguised as private key folders. The tool represents a significant development in the field of Russian cyber attacks, as it combines credential phishing , keylogging and RDP hijacking techniques via Fast Reverse Proxy (FRP) Tunnels.

According to Censys, the CTRL toolkit is built with .NET and includes various executable files that facilitate credential theft, keystroke logging, and Remote Desktop Protocol (RDP) hijacking.
Researcher Andrew Northern from Censys noted that “the executables provide encrypted payload loading, credential collection via an advanced Windows Hello phishing UI, keylogging, RDP session hijacking, and reverse proxy tunneling via FRP.”
See also: Konni Group exploits KakaoTalk to spread EndRAT Malware
Technical Details of the CTRL Toolkit and Attack Mechanisms
The platform reported that it retrieved CTRL from an open directory in February 2026.The attack chains that distribute the toolkit rely on a weaponized LNK file (“Private Key #kfxm7p9q_yek.lnk”) with a folder icon to trick users into double-clicking it. This triggers a multi-stage process, where each stage decrypts or decompresses the next, leading to the deployment of the toolkit.
The LNK dropper is designed to launch a hidden PowerShell, which then deletes existing persistence mechanisms from the Windows Startup . It also decodes a Base64-encoded blob and executes it in memory.
The stager checks TCP connectivity to hui228[.]ru:7000 and downloads next-stage payloads from the server. In addition, it modifies firewall rules, creates persistence using scheduled tasks, creates backdoor local users, and creates a cmd.exe shell server on port 5267 , accessible via the FRP tunnel.
One of the downloaded payloads, “ctrl.exe“, acts as a .NET loader to launch an embedded payload, the CTRL Management Platform, which can act as either a server or a client depending on the command-line arguments. Communication is done via a Windows named pipe.
See also: Microsoft: IRS Phishing Attack Hit 29,000 Users with RMM Malware

As Censys, “the dual-mode design means that the operator deploys ctrl.exe once to the victim (via the stager), then interacts with it by running the ctrl.exe client over the FRP-tunneled RDP session. The named pipe architecture keeps all C2 command traffic local to the victim’s machine — nothing crosses the network except the RDP session itself.”
The supported commands allow the malware to collect system information, launch a module designed to collect credentials, and start a keylogger as a background service (if configured as a server) to record all keystrokes in a file named “C:\Temp\keylog.txt”.
The credential collection component launches as a Windows Presentation Foundation (WPF) that emulates a real Windows PIN verification prompt to capture the system PIN. The module blocks attempts to escape the phishing window, via keyboard shortcuts such as Alt+Tab, Alt+F4 , or F4, and validates the entered PIN against the real Windows credential prompt via UI automation using the SendKeys().
As Northern, “if the PIN is rejected, the victim is returned with an error message. The window remains open even if the PIN is successfully validated against the real Windows authentication system. The captured PIN is recorded with the prefix [STEALUSER PIN CAPTURED] in the same keylog file used by the background keylogger.”
See also: Trivy Attack: Malware on Docker Hub and Kubernetes Wiper
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

One of the commands embedded in the toolkit allows it to send toast notifications disguised as browsers such as Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Vivaldi, Yandex , and Iron to conduct additional credential theft or deliver other payloads. The other two payloads installed as part of the attack are:
- FRPWrapper.exe, a Go DLL that is loaded into memory to create reverse tunnels for RDP and a raw TCP shell through the operator's FRP server, and
- RDPWrapper.exe, which allows unlimited simultaneous RDP sessions.
The CTRL toolkit is part of a broader trend of resurgence in Russian cyberattacks, with groups like APT28 moving from simple implants to sophisticated toolkits. Similar developments include the LAMEHUG malware targeting Ukrainian government officials and the NOROBOT DLL using ClickFix lures. Experts recommend detecting exposed RDP/VNC with weak authentication, deploying behavioral analytics for abnormal administrator access, and blocking the execution of LNK files in emails.
