[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9nzAhQyY1cF8clCj2A4zp9KhPprqmejV-nMD4d2Q1XE":3},{"article":4,"iocs":36,"watch_terms":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":23},"17c68f3f-14c9-4d0e-93f6-cb697576475c","Under CTRL: Dissecting a Previously Undocumented Russian .Net Access Framework - Censys","under-ctrl-dissecting-a-previously-undocumented-russian-net-access-framework-cen","Censys ARC discovered a previously undocumented, Russian-origin remote access toolkit dubbed \"CTRL.\" Learn about the malware and how it works.","Censys ARC researchers have identified a previously unknown remote access framework called CTRL with Russian origins. The malware is built on .NET and functions as a remote access toolkit. This discovery expands the known landscape of Russian-origin cyber attack tools.","Censys discovers CTRL, undocumented Russian .NET remote access toolkit.","US: +1-888-985-5547 Intl: +1-877-438-9159 connect@censys.com Why Censys Censys Platform Censys Search AI at Censys Threat Hunting Attack Surface Management Censys for Government Partners Request Demo Explore Careers Security Advisories Blog Contact Us Community Documentation Pricing Popular 2025 State of the Internet Report Cloud Security Assessment Tools Infrastructure Monitoring Vulnerability Management Tools Top Ransomware Attack Vectors Attack Surface Mapping Subscribe to our newsletter YoutubeLinkedinX500px Why Censys Censys Platform Censys Search AI at Censys Threat Hunting Attack Surface Management Censys for Government Partners Request Demo Explore Careers Security Advisories Blog Contact Us Community Documentation Pricing Popular 2025 State of the Internet Report Cloud Security Assessment Tools Infrastructure Monitoring Vulnerability Management Tools Top Ransomware Attack Vectors Attack Surface Mapping Subscribe to our newsletter YoutubeLinkedinX500px","https:\u002F\u002Fcensys.com\u002Fblog\u002Funder-ctrl-dissecting-a-previously-undocumented-russian-net-access-framework\u002F","https:\u002F\u002Fcensys.com\u002Fwp-content\u002Fuploads\u002FCTRL-Blog-Featured-Image-1200x627-1.png","2026-03-27T18:43:36+00:00","2026-03-27T19:00:11.793+00:00",7,[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":18,"icon":20,"name":21,"slug":22},null,"Malware","malware",[24,29,31],{"category":25},{"id":26,"icon":20,"name":27,"slug":28},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":30},{"id":18,"icon":20,"name":21,"slug":22},{"category":32},{"id":33,"icon":20,"name":34,"slug":35},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[37],{"type":22,"value":38,"context":39},"CTRL","Previously undocumented Russian-origin .NET remote access toolkit discovered by Censys ARC",[]]