Censys researchers disclosed a previously undocumented Russian-origin remote access toolkit dubbed CTRL that is delivered through malicious Windows .lnk files disguised as private key folders. The shortcut launches hidden PowerShell, loads a .NET stager from the registry, retrieves additional payloads from hui228[.]ru:7000, and installs components that provide persistence, firewall modifications, local backdoor accounts, and a shell server. Researchers said the framework supports credential phishing, keylogging, and remote access while keeping much of its command activity local through named pipes, with ctrl.exe acting as the command platform.
CTRL also includes a Windows Hello-style phishing module that mimics the legitimate PIN prompt and validates stolen PINs against the real credential dialog, alongside a keylogger that writes to C:\Temp\keylog.txt. To give operators stealthy hands-on-keyboard access, the toolkit deploys components such as FRPWrapper.exe and RDPWrapper.exe to create Fast Reverse Proxy tunnels and enable concurrent RDP sessions instead of relying on traditional network-visible C2 beaconing. Censys linked the infrastructure to hui228[.]ru and FRP relay activity on 194.33.61.36 and later 109.107.168.18, and said the toolkit and related binaries were not present in major public malware repositories at the time of analysis, indicating a privately developed framework with limited public exposure.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
The Hacker News summarized Censys' findings on CTRL, highlighting its malicious shortcut delivery, in-memory PowerShell execution, contact with hui228[.]ru:7000, firewall changes, local backdoor users, and tunneled RDP access. The report did not introduce a separate new incident but amplified the public disclosure of the toolkit's capabilities and infrastructure.
Censys ARC published research detailing the Russian-origin CTRL remote access toolkit, including its LNK-based infection chain, Windows Hello PIN phishing, keylogging, persistence, and RDP hijacking via FRP tunnels. The researchers noted the binaries and infrastructure were not present in major public malware repositories or threat intelligence sources at the time of publication.
Censys identified operator infrastructure for the Russian-origin CTRL framework using hui228[.]ru and FRP relay activity on 194.33.61.36, later shifting to 109.107.168.18, both hosted by Partner Hosting LTD in Frankfurt. The servers exposed FRP, HTTP, and vulnerable OpenSSH services supporting the toolkit's reverse-tunneled remote access model.
In February 2026, Censys recovered the previously undocumented CTRL toolkit from an open directory at 146.19.213[.]155. Analysis showed the .NET-based framework was delivered via malicious Windows LNK files and designed for stealthy hands-on-keyboard access using local named pipes and FRP-tunneled RDP.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.