logo

CrystalX RAT: new MaaS malware combines spyware, stealer, and remote access

ID: 395f6a0a-bc31-5d9b-9fda-176937024b9e

STIX ID: report--395f6a0a-bc31-5d9b-9fda-176937024b9e

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CrystalX RAT is a newly discovered MaaS (first seen Jan 2026, reported Mar 2026) marketed via Telegram and YouTube that bundles RAT, stealer, keylogger, clipboard clipper, spyware and prank functionality. It includes an auto-builder with customization (geoblocking, anti-analysis), compresses/encrypts payloads (zlib, ChaCha20), uses a WebSocket-based C2 to exfiltrate JSON data, and implements multiple anti-analysis checks; dozens of victims (mainly in Russia) are reported and its active promotion and ongoing development indicate likely wider spread.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.