Rpdpatch
Overview
Executive Summary
RPDPatch (or RDP Patcher) is a classification for tools, often flagged as HackTools or Riskware, designed to circumvent Microsoft Windows licensing restrictions. Standard Windows client operating systems (like Windows 10/11 Pro) only allow a single, concurrent Remote Desktop Protocol (RDP) session. RPDPatch alters system DLLs (specifically `termsrv.dll`) to allow multiple, simultaneous RDP connections to a single client machine. While sometimes used legitimately by aggressive IT administrators, threat actors heavily abuse this tool to establish persistent, interactive remote access to compromised systems without interrupting the legitimate user's session.Infection Vector and Technical Capabilities
RPDPatch is a post-exploitation tool. It is manually deployed and executed by an attacker who has already breached the endpoint, escalated privileges to Administrator or SYSTEM, and wishes to solidify their backdoor access. Upon execution, RPDPatch modifies core OS components:- DLL Patching (`termsrv.dll`): The tool forcibly modifies the binary code of the Terminal Services DLL (`termsrv.dll`) in the `System32` directory. It patches the specific conditional jumps that enforce the single-session connection limit, effectively unlocking Windows Server-like terminal services on a client OS.
- Service Restart: After patching the DLL, the tool restarts the Remote Desktop Services (`TermService`) to apply the changes.
- Covert Access: Once patched, the attacker can connect via RDP to the compromised machine at any time, using a stolen credential or a newly created hidden admin account, without kicking the legitimate user off the computer. This allows for highly stealthy, interactive lateral movement.
Threat Assessment
The unauthorized detection of an RPDPatch is a critical indicator of a severe, ongoing compromise. It signifies that an attacker has gained complete administrative control over the endpoint, is actively establishing persistent backdoors, and is likely using the machine as a pivot point to attack the rest of the network via RDP.Incident Response and Remediation
- Immediate Network Isolation: Isolate the endpoint immediately to terminate the attacker's active RDP session and prevent further lateral movement.
- Forensic Investigation of User Accounts: Analysts must immediately investigate the local SAM database and Active Directory logs to identify which accounts the attacker used to authenticate via the patched RDP service, and look for any newly created, hidden administrator accounts.
- Total Re-imaging: Because the attacker had interactive SYSTEM-level access and actively modified core Windows DLLs, attempting to manually revert the `termsrv.dll` patch is insufficient. The endpoint must undergo a complete bare-metal wipe and re-image from a trusted baseline.
Known aliases
Threat reports may refer to this family under multiple names:
MITRE ATT&CK Techniques
This family has been observed using the following ATT&CK techniques: T1563.002 T1021.001 T1543.003
Generated Detections (Boilerplate)
These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.
YARA Rule
rule MALWARE_WIN_RPDPATCH {
meta:
description = "Detects Rpdpatch (backdoor)"
author = "SystemHelpdesk Boilerplate Generator"
date = "2026-07-06"
strings:
$s1 = "rpdpatch" ascii wide nocase
$s2 = "hacktool.rpdpatch" ascii wide nocase
$s3 = "riskware.rdppatcher" ascii wide nocase
$s4 = "tool.rdpwrap" ascii wide nocase
$s5 = "win32/patch.rdp" ascii wide nocase
condition:
uint16(0) == 0x5a4d and any of them
}Sigma Rule
title: Suspicious Rpdpatch Activity
id: a4162fcfa9db32568c09da2340f8867d
status: experimental
description: Detects generic indicators of the rpdpatch malware family.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- "*rpdpatch*"
- "*hacktool.rpdpatch*"
- "*riskware.rdppatcher*"
- "*tool.rdpwrap*"
- "*win32/patch.rdp*"
condition: selection
level: mediumReferences & External Analysis
- Search "rpdpatch" on VirusTotal (External Analysis)
Frequently Asked Questions
How do I remove the Rpdpatch Backdoor from Windows?
Manual removal of Rpdpatch is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.
Is Rpdpatch a virus or a Backdoor?
Rpdpatch is classified as a Backdoor. Unlike traditional viruses that infect files, modern malware like Rpdpatch typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.
What are the main symptoms of a Rpdpatch infection?
Symptoms of Rpdpatch can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.
Related Families (Category: backdoor)
Explore other malware families in the same category:
Protect Your Network Against Backdoors
Want to prevent Rpdpatch and similar threats from compromising your organization? Read our comprehensive defensive guide: Backdoor & RAT Protection.
Machine-readable
Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/rpdpatch.json
Ecosystem & Interactive Environments
This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.