Hackers Push CrystalX Malware-as-a-Service Through Telegram With Stealer and RAT Features
ID: abfd3c65-da89-5da6-9c24-cba51dfb7b18
STIX ID: report--abfd3c65-da89-5da6-9c24-cba51dfb7b18
Feed Name: cybersecurityNews.com
Securelist analysts identified and analyzed CrystalX, a Malware-as-a-Service (MaaS) platform sold via private Telegram channels that bundles a Go-based RAT with credential theft, keylogging, clipboard hijacking, spyware and prankware features. Discovered in early 2026 and actively developed, CrystalX employs strong evasion techniques (zlib compression + ChaCha20 encryption, VM/debugger/proxy detection, Windows API patching), uses hard-coded WebSocket C2 domains (webcrystal.lol, webcrystal.sbs, crystalxrat.top), and has been linked to dozens of infection attempts, primarily in Russia; detection signatures are available from vendors like Kaspersky.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
