Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI Chatbots Claude, ChatGPT, Copilot Used in Malware Attacks
August 20, 2026
Critical CyberPanel RCE Chain (CVE-2024-7067) Lets Attackers Gain Server Shell
August 20, 2026
ZombieLoad Flaw Exploits Intel CPUs, Exposes Sensitive Data
August 20, 2026
Home/Threats/CrystalX Malware-as-a-Service Spreads via Telegram, Offers Stealer and RAT
Threats

CrystalX Malware-as-a-Service Spreads via Telegram, Offers Stealer and RAT

Key Takeaways CrystalX is a new Malware-as-a-Service (MaaS) offering actively promoted on Telegram channels since March 2026. It functions as a sophisticated Remote Access Trojan (RAT) and credential...

Marcus Rodriguez
Marcus Rodriguez
April 1, 2026 4 Min Read
60 0

Key Takeaways

  • CrystalX is a new Malware-as-a-Service (MaaS) offering actively promoted on Telegram channels since March 2026.
  • It functions as a sophisticated Remote Access Trojan (RAT) and credential stealer, featuring keylogging, clipboard hijacking, spyware, and unique “prankware” capabilities.
  • The malware is designed with advanced anti-analysis and evasion techniques, including encryption, anti-VM checks, and patching of critical Windows security functions.
  • Dozens of victims, primarily in Russia, have already been affected, with the threat capable of targeting users globally.
  • Organizations should implement robust endpoint detection, network monitoring, and keep security software updated to mitigate the risk.

CrystalX: A Hybrid Malware-as-a-Service Blending Espionage with Prankware

A new and dangerous Malware-as-a-Service (MaaS) platform named CrystalX is being openly advertised to cybercriminals through private Telegram channels. This versatile malware, first identified in March 2026, bundles a comprehensive suite of malicious capabilities, including remote access, credential theft, keylogging, and clipboard hijacking, alongside a peculiar set of “prankware” tools.

Table Of Content

  • Key Takeaways
  • CrystalX: A Hybrid Malware-as-a-Service Blending Espionage with Prankware
  • Evolution from Webcrystal RAT to CrystalX
  • Unusual Feature Set and Global Reach
  • Detection Evasion and Anti-Analysis Tactics
  • What You Should Do

The emergence of CrystalX highlights a concerning trend where sophisticated attack tools are modularized and offered on a subscription basis, making advanced cyber capabilities accessible to a broader range of threat actors.

Evolution from Webcrystal RAT to CrystalX

CrystalX’s origins can be traced back to January 2026, when its developer initially launched a tool called Webcrystal RAT within a private Telegram group frequented by other RAT developers. Early analysis revealed striking similarities between Webcrystal RAT’s control panel and an older malware known as WebRAT, also referred to as Salat Stealer. Both tools were developed using the Go programming language, and the bot used to distribute access keys for Webcrystal RAT closely mirrored the infrastructure employed by WebRAT.

Following criticism regarding its perceived lack of originality, the developer rebranded the malware as CrystalX RAT. This rebranding effort included establishing a dedicated Telegram channel for marketing, complete with access key giveaways and polls, and even launching a YouTube channel to demonstrate the malware’s expanding feature set and capabilities.

WebRAT - Panel layout similarities (Source - Securelist)
WebRAT – Panel layout similarities (Source – Securelist)

Unusual Feature Set and Global Reach

Analysts at Securelist conducted a detailed technical analysis of CrystalX, confirming its active deployment and noting that its feature set extends beyond typical commercial RATs. The malware is sold across three subscription tiers, providing buyers with access to a web-based control panel. This panel offers a wide array of functions, from discreet file exfiltration to live remote screen control.

A distinguishing characteristic of CrystalX is its integration of serious espionage capabilities with an entire section of “prank commands” designed for victim harassment and disruption. This unusual combination makes CrystalX a particularly noteworthy threat in the current MaaS landscape.

While infection attempts have been predominantly observed in Russia, CrystalX lacks any inherent geographic restrictions, allowing any subscriber to deploy it against targets worldwide. Kaspersky products are capable of detecting this threat under various signatures, including Backdoor.Win64.CrystalX, Trojan.Win64.Agent, and Trojan.Win32.Agentb.gen.

Ongoing development of new implant versions indicates that CrystalX is still actively being refined. As the attacker intensifies promotional efforts, the malware’s subscriber base is expected to expand, increasing its potential impact.

Detection Evasion and Anti-Analysis Tactics

CrystalX incorporates sophisticated techniques to evade detection and hinder analysis. Each malware implant is initially compressed using zlib and then encrypted with the ChaCha20 algorithm, employing a hard-coded 32-byte key and a 12-byte nonce. This encryption significantly complicates static analysis efforts.

The malware’s auto-builder, accessible through the control panel, allows operators to configure anti-analysis features during the build process. These options include selective geoblocking by country and the ability to customize executable icons, further complicating attribution and detection.

During execution, CrystalX performs a series of checks to determine if it is operating within an analysis environment. It inspects a Windows registry value to detect the presence of proxy tools like Fiddler, Burp Suite, or mitmproxy, and subsequently blacklists their process names. A separate routine is dedicated to virtual machine detection, examining running processes, installed guest tools, and hardware characteristics to confirm operation on a genuine system.

An anti-attach loop continuously monitors the debug flag, debug port, hardware breakpoints, and program execution timing to thwart any attempts at debugger attachment. Furthermore, CrystalX patches critical Windows functions such as AmsiScanBuffer, EtwEventWrite, and MiniDumpWriteDump. This action disables security instrumentation and memory dumping tools that cybersecurity analysts frequently rely on during investigations, making forensic analysis significantly more challenging.

CrystalX RAT Implants (Source - Securelist)
CrystalX RAT Implants (Source – Securelist)

After successfully bypassing these checks, CrystalX establishes a connection to its command-and-control (C2) server via a hard-coded WebSocket URL to begin collecting system data. Known C2 domains associated with CrystalX include webcrystal.lol, webcrystal.sbs, and crystalxrat.top.

What You Should Do

  • Organizations should immediately block the known C2 domains (webcrystal.lol, webcrystal.sbs, crystalxrat.top) at their network perimeter.
  • Monitor network traffic for unusual outbound WebSocket connections, which could indicate CrystalX activity.
  • Investigate any executable exhibiting anti-debugging behaviors or attempts to patch critical Windows functions.
  • Ensure all endpoint protection tools, including antivirus and Endpoint Detection and Response (EDR) solutions, are regularly updated with the latest threat intelligence.
  • Implement robust email and web filtering to prevent initial infection vectors, as MaaS offerings often rely on phishing or malicious downloads.
  • Educate users about the risks of suspicious links and attachments to prevent the download and execution of malware.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarePatchSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

ShinyHunters claims Cisco data leak, source code theft

Next Post

EtherRAT, EtherHiding Malware Conceals Infrastructure on Ethereum Blockchain

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Claude AI Finds SAML Security Flaws That Can Let Attackers Take Over Accounts
August 20, 2026
Critical Zimbra RCE Vulnerability CVE-2022-27925 Actively Exploited
August 20, 2026
T-Mobile Physically Disconnects Network to Expel Chinese Hackers
August 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us