Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels

Cybersecurity experts have uncovered a Russian-origin remote access toolkit that is disseminated using malicious Windows shortcut (LNK) files that pose as private key folders.

According to Censys, the CTRL toolkit was created specifically using.NET and contains a number of executables that enable reverse tunneling via Fast Reverse Proxy (FRP), credential phishing, keylogging, and Remote Desktop Protocol (RDP) hijacking.

According to Censys security researcher Andrew Northern, the executables offer keylogging, RDP session hijacking, encrypted payload loading, credential harvesting via a polished Windows Hello phishing UI, and reverse proxy tunneling through FRP.

According to the attack surface management platform, in February 2026, CTRL was recovered from an open directory at 146.19.213[.]155. A weaponized LNK file (“Private Key #kfxm7p9q_yek.lnk”) with a folder icon is used by attack chains that distribute the toolkit to deceive users into double-clicking it.

This starts a series of steps, each of which decrypts or decompresses the previous one until the toolkit is deployed read more about Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *