Russian CTRL toolkit spread via malicious LNK files in February 2026, routing C2 through FRP-tunneled RDP to evade detection.
The malware at the center of it, dubbed Omnistealer by investigators, uses public blockchains not just for payments, but as ...