logo

New CrystalRAT malware adds RAT, stealer and prankware features

ID: ea185b54-f966-5fb2-9c0d-733ed7515f37

STIX ID: report--ea185b54-f966-5fb2-9c0d-733ed7515f37

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-04-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky researchers describe CrystalX (CrystalRAT), a Go-based Malware-as-a-Service marketed on Telegram and YouTube that offers remote access, extensive data-stealing functionality (browser and desktop app targeting), real-time keylogging and clipboard clippers, and a unique set of prankware features; the malware uses an automated builder, anti-analysis protections, ChaCha20-encrypted zlib payloads, and a WebSocket C2 for operator control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.