HomeSecurityRussian CTRL Toolkit: New malware steals passwords and data

Russian CTRL Toolkit: New malware steals passwords and data

Cybersecurity researchers have discovered an advanced CTRL toolkit of Russian origin, distributed via malicious Windows LNK files disguised as private key folders. The tool represents a significant development in the field of Russian cyber attacks, as it combines credential phishing , keylogging and RDP hijacking techniques via Fast Reverse Proxy (FRP) Tunnels.

CTRL Toolkit

According to Censys, the CTRL toolkit is built with .NET and includes various executable files that facilitate credential theft, keystroke logging, and Remote Desktop Protocol (RDP) hijacking.

Researcher Andrew Northern from Censys noted that “the executables provide encrypted payload loading, credential collection via an advanced Windows Hello phishing UI, keylogging, RDP session hijacking, and reverse proxy tunneling via FRP.”

See also: Konni Group exploits KakaoTalk to spread EndRAT Malware

Technical Details of the CTRL Toolkit and Attack Mechanisms

The platform reported that it retrieved CTRL from an open directory in February 2026.The attack chains that distribute the toolkit rely on a weaponized LNK file (“Private Key #kfxm7p9q_yek.lnk”) with a folder icon to trick users into double-clicking it. This triggers a multi-stage process, where each stage decrypts or decompresses the next, leading to the deployment of the toolkit.

The LNK dropper is designed to launch a hidden PowerShell, which then deletes existing persistence mechanisms from the Windows Startup . It also decodes a Base64-encoded blob and executes it in memory.

The stager checks TCP connectivity to hui228[.]ru:7000 and downloads next-stage payloads from the server. In addition, it modifies firewall rules, creates persistence using scheduled tasks, creates backdoor local users, and creates a cmd.exe shell server on port 5267 , accessible via the FRP tunnel.

One of the downloaded payloads, “ctrl.exe“, acts as a .NET loader to launch an embedded payload, the CTRL Management Platform, which can act as either a server or a client depending on the command-line arguments. Communication is done via a Windows named pipe.

See also: Microsoft: IRS Phishing Attack Hit 29,000 Users with RMM Malware

Russian CTRL Toolkit: New malware steals passwords and data

As Censys, “the dual-mode design means that the operator deploys ctrl.exe once to the victim (via the stager), then interacts with it by running the ctrl.exe client over the FRP-tunneled RDP session. The named pipe architecture keeps all C2 command traffic local to the victim’s machine — nothing crosses the network except the RDP session itself.”

The supported commands allow the malware to collect system information, launch a module designed to collect credentials, and start a keylogger as a background service (if configured as a server) to record all keystrokes in a file named “C:\Temp\keylog.txt”.

The credential collection component launches as a Windows Presentation Foundation (WPF) that emulates a real Windows PIN verification prompt to capture the system PIN. The module blocks attempts to escape the phishing window, via keyboard shortcuts such as Alt+Tab, Alt+F4 , or F4, and validates the entered PIN against the real Windows credential prompt via UI automation using the SendKeys().

As Northern, “if the PIN is rejected, the victim is returned with an error message. The window remains open even if the PIN is successfully validated against the real Windows authentication system. The captured PIN is recorded with the prefix [STEALUSER PIN CAPTURED] in the same keylog file used by the background keylogger.”

See also: Trivy Attack: Malware on Docker Hub and Kubernetes Wiper

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Russian CTRL Toolkit: New malware steals passwords and data

One of the commands embedded in the toolkit allows it to send toast notifications disguised as browsers such as Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Vivaldi, Yandex , and Iron to conduct additional credential theft or deliver other payloads. The other two payloads installed as part of the attack are:

  • FRPWrapper.exe, a Go DLL that is loaded into memory to create reverse tunnels for RDP and a raw TCP shell through the operator's FRP server, and
  • RDPWrapper.exe, which allows unlimited simultaneous RDP sessions.

The CTRL toolkit is part of a broader trend of resurgence in Russian cyberattacks, with groups like APT28 moving from simple implants to sophisticated toolkits. Similar developments include the LAMEHUG malware targeting Ukrainian government officials and the NOROBOT DLL using ClickFix lures. Experts recommend detecting exposed RDP/VNC with weak authentication, deploying behavioral analytics for abnormal administrator access, and blocking the execution of LNK files in emails.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS