Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels
Cybersecurity experts have uncovered a Russian-origin remote access toolkit that is disseminated using malicious Windows shortcut (LNK) files that pose as private key folders.
According to Censys, the CTRL toolkit was created specifically using.NET and contains a number of executables that enable reverse tunneling via Fast Reverse Proxy (FRP), credential phishing, keylogging, and Remote Desktop Protocol (RDP) hijacking.
According to Censys security researcher Andrew Northern, the executables offer keylogging, RDP session hijacking, encrypted payload loading, credential harvesting via a polished Windows Hello phishing UI, and reverse proxy tunneling through FRP.
According to the attack surface management platform, in February 2026, CTRL was recovered from an open directory at 146....

