CTRL is a previously undocumented, Russian-linked/Russian-origin remote access toolkit targeting Windows systems. Censys ARC described it as a custom-built .NET Framework 4.7.2 toolkit that combines credential phishing, keylogging, Remote Desktop Protocol (RDP) hijacking, persistence, privilege escalation, and Fast Reverse Proxy (FRP)-based reverse tunneling in a single post-exploitation package. The tooling was assessed as likely privately used rather than broadly distributed, and at the time of reporting its artifacts were not present in major public malware repositories or threat intelligence feeds.
Observed delivery used a malicious Windows LNK file disguised as a folder/private key archive, including the lure "Private Key #kfxm7p9q_yek.lnk." The shortcut launches hidden, multi-stage PowerShell that decodes and executes payloads in memory, wipes the Startup folder, decompresses a .NET stager, stores payloads in registry locations under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ using values such as ShellStateVersion1, IconSizeVersion1, and IconUnderlineVersion1, and downloads additional components from hui228[.]ru. The stager establishes persistence via scheduled tasks including DriverSvcTask, NetTcpSvc, TermSvcHost, and WindowsHealthMonitor, modifies firewall rules, checks connectivity to hui228[.]ru:7000, and can disconnect VPN/PPP interfaces with rasdial.exe /DISCONNECT.
For privilege escalation and persistence, CTRL uses a fodhelper.exe-based UAC bypass with a signed Microsoft binary-assisted launcher. It may attempt to blank existing user passwords for RDP access or create hidden local accounts such as Administrator, Admin, or Windows with password ADAD and add them to privileged groups. It deploys ctrl.exe to C:\ProgramData\SystemTools\ctrl.exe, writes FRP configuration to C:\ProgramData\frp\frpc.toml, and maintains access across reboots.
A core capability is stealthy hidden RDP access. RDPWrapper.exe patches termsrv.dll, installs RDP Wrapper, adds Defender exclusions, and enables unlimited/concurrent RDP sessions without alerting the victim. FRPWrapper.exe decrypts and manually maps an embedded FRP v0.65.0 Go DLL in memory to establish reverse tunnels for RDP and a raw TCP shell. Censys reported that operator activity is routed through FRP tunnels and compromised RDP sessions rather than conventional malware beaconing. Local operator control is provided through the named pipe ctrlPipe by the CTRL Management Platform v2.0.0, which supports commands including info, help, logs, stealuser, shadow, copy, toast, and arbitrary PowerShell execution.
CTRL also includes credential theft and surveillance functions. It runs a background keylogger that records keystrokes and active window titles to C:\Temp\keylog.txt. Its StealUser module presents a fake Windows Hello PIN prompt that mimics the legitimate Windows interface, uses the victim's real display name, account photo, and theme, blocks escape shortcuts such as Alt+Tab and Alt+F4, and validates entered PINs against the real Windows credential prompt. Captured PINs are logged to the keylog file, including with the prefix "[STEALUSER PIN CAPTURED]." The toolkit can also send browser-impersonating toast notifications for social engineering.
Associated infrastructure identified by Censys includes hui228[.]ru, 194.33.61.36, and 109.107.168.18. The domain hui228[.]ru was used for payload hosting and dynamic DNS-backed command/relay functions; 194.33.61.36 served payloads and acted as an FRP relay; 109.107.168.18 was observed as a secondary FRP relay on port 7000. Additional notable artifacts and indicators mentioned in the reporting include C:\ProgramData\frp\frpc.toml containing FRP settings and token ADAD, the registry payload storage under Explorer-related keys, the named pipe ctrlPipe, and suspicious outbound FRP traffic to the identified infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The stager then creates scheduled tasks, adds firewall rules, downloads additional components, and prepares the system for long-term access.
In addition, the malware runs a background keylogger and supports command execution via a named pipe named ctrlPipe.
According to Censys, the LNK file launches hidden PowerShell code that decodes and runs a multi-stage loader entirely in memory.
TCP shell : Starts a raw cmd.exe shell server on port 5267...
The bypass writes a VBS launcher to C:\Temp\win_update.vbs... and then launches fodhelper.exe via explorer.exe.
The attack starts with a weaponized shortcut file disguised as a folder named like a private key archive. According to Censys, the LNK file launches hidden PowerShell code that decodes and runs a multi-stage loader entirely in memory.
...supports command execution via a named pipe named ctrlPipe. According to Censys, this allows the operator to control the infected machine locally via the compromised RDP session rather than using a noisy traditional command-and-control channel.
The stager then creates scheduled tasks, adds firewall rules, downloads additional components, and prepares the system for long-term access.
Attempts to blank existing user passwords for RDP access. If that fails, creates a hidden local account... adds it to Administrators, Remote Desktop Users, and Remote Management Users...
Censys ARC found that the malware stores payloads inside Windows registry keys under Explorer-related paths. Hence, they blend in with normal system data.
The stager then creates scheduled tasks, adds firewall rules, downloads additional components, and prepares the system for long-term access.
Attempts to blank existing user passwords for RDP access. If that fails, creates a hidden local account... adds it to Administrators, Remote Desktop Users, and Remote Management Users...
The base64 blob decodes through three layers before executing the .NET stager... Variable names are randomized... String literals used in registry paths are split and reassembled using character arithmetic obfuscation.
It uses SHELL32.dll icon index 3 (the folder icon) so it appears as a directory in Explorer, not an executable.
The bypass cleans up all registry keys and the VBS file after execution.
wlrmdr.exe is a signed Microsoft binary... used here as a LOLBin. This routes execution through it rather than launching the VBS script directly...
ctrl.exe deployment : Downloads ctrl.exe to C:\ProgramData\SystemTools\ctrl.exe (hidden directory)... FRP configuration : Writes C:\ProgramData\frp\frpc.toml (hidden directory)...
One of the most dangerous parts of CTRL is its ability to enable hidden RDP access. According to the Censys ARC report, the malware patches termsrv.dll and installs RDP Wrapper so attackers can create concurrent remote desktop sessions without alerting the victim.
To reduce network visibility, CTRL uses Fast Reverse Proxy (FRP) to establish reverse tunnels back to operator-controlled infrastructure.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom .NET remote access toolkit for Windows that uses a weaponized LNK and in-memory PowerShell loader, stores payloads in registry keys, establishes persistence via scheduled tasks and firewall rules, bypasses UAC, enables hidden concurrent RDP sessions by patching termsrv.dll and installing RDP Wrapper, presents a fake Windows Hello PIN prompt to steal credentials, logs keystrokes, and uses FRP reverse tunnels plus a named pipe for stealthy operator access.
A Russian-origin custom .NET remote access toolkit delivered via malicious LNK files. It supports encrypted payload loading, credential harvesting through a fake Windows Hello PIN prompt, keylogging, RDP session hijacking, local named-pipe command handling, persistence via scheduled tasks, firewall modification, creation of backdoor local users, and operator access through FRP-tunneled RDP and shell services.
A custom-built .NET remote access toolkit distributed via malicious LNK files. It provides encrypted payload loading, Windows Hello-themed credential phishing, keylogging, RDP session hijacking, reverse proxy tunneling through FRP, persistence via registry and scheduled tasks, UAC bypass, hidden admin account creation, and hands-on-keyboard access through a local named-pipe command interface.
A previously undocumented Russian-origin remote access toolkit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.