CrystalX Malware-as-a-Service Spreads via Telegram With Stealer, RAT Tools
ID: 3d511b4e-e91f-5ac2-aff1-9601b147869c
STIX ID: report--3d511b4e-e91f-5ac2-aff1-9601b147869c
Feed Name: GBHackers
Threat Score
Researchers identified CrystalX RAT — a commercially promoted malware-as-a-service combining RAT, stealer, keylogger, clipboard-clipper, spyware, VNC and prank modules — being marketed via private Telegram channels and YouTube in early 2026; the platform includes an automated builder, anti-analysis protections, WebSocket C2, credential and browser extraction, and active development that may broaden its reach beyond current Russia-centric infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
