logo

A laughing RAT: CrystalX combines spyware, stealer, and prankware features

ID: cd22793b-6dcd-592d-b882-eb24db4b1949

STIX ID: report--cd22793b-6dcd-592d-b882-eb24db4b1949

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2026-04-01

Date Updated: 2026-04-29

Author: GReAT

...
...

Kaspersky analysts describe an active MaaS campaign (CrystalX RAT) being promoted on Telegram/YouTube that provides third parties with a Go‑based RAT including stealer, keylogger, clipper, VNC remote control, microphone/camera capture, extensive anti‑analysis/builder options and a surprising set of prankware features; the report includes technical details, builder/anti‑debug behaviors, command capabilities, and several C2 and sample hashes, noting active development and infection attempts observed in Russia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.