logo

Hackers Push CrystalX Malware-as-a-Service Through Telegram With Stealer and RAT Features

ID: abfd3c65-da89-5da6-9c24-cba51dfb7b18

STIX ID: report--abfd3c65-da89-5da6-9c24-cba51dfb7b18

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-01

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Securelist analysts identified and analyzed CrystalX, a Malware-as-a-Service (MaaS) platform sold via private Telegram channels that bundles a Go-based RAT with credential theft, keylogging, clipboard hijacking, spyware and prankware features. Discovered in early 2026 and actively developed, CrystalX employs strong evasion techniques (zlib compression + ChaCha20 encryption, VM/debugger/proxy detection, Windows API patching), uses hard-coded WebSocket C2 domains (webcrystal.lol, webcrystal.sbs, crystalxrat.top), and has been linked to dozens of infection attempts, primarily in Russia; detection signatures are available from vendors like Kaspersky.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.