CrystalX Malware-as-a-Service Spreads via Telegram, Offers Stealer and RAT
Key Takeaways CrystalX is a new Malware-as-a-Service (MaaS) offering actively promoted on Telegram channels since March 2026. It functions as a sophisticated Remote Access Trojan (RAT) and credential...
Key Takeaways
- CrystalX is a new Malware-as-a-Service (MaaS) offering actively promoted on Telegram channels since March 2026.
- It functions as a sophisticated Remote Access Trojan (RAT) and credential stealer, featuring keylogging, clipboard hijacking, spyware, and unique “prankware” capabilities.
- The malware is designed with advanced anti-analysis and evasion techniques, including encryption, anti-VM checks, and patching of critical Windows security functions.
- Dozens of victims, primarily in Russia, have already been affected, with the threat capable of targeting users globally.
- Organizations should implement robust endpoint detection, network monitoring, and keep security software updated to mitigate the risk.
CrystalX: A Hybrid Malware-as-a-Service Blending Espionage with Prankware
A new and dangerous Malware-as-a-Service (MaaS) platform named CrystalX is being openly advertised to cybercriminals through private Telegram channels. This versatile malware, first identified in March 2026, bundles a comprehensive suite of malicious capabilities, including remote access, credential theft, keylogging, and clipboard hijacking, alongside a peculiar set of “prankware” tools.
Table Of Content
The emergence of CrystalX highlights a concerning trend where sophisticated attack tools are modularized and offered on a subscription basis, making advanced cyber capabilities accessible to a broader range of threat actors.
Evolution from Webcrystal RAT to CrystalX
CrystalX’s origins can be traced back to January 2026, when its developer initially launched a tool called Webcrystal RAT within a private Telegram group frequented by other RAT developers. Early analysis revealed striking similarities between Webcrystal RAT’s control panel and an older malware known as WebRAT, also referred to as Salat Stealer. Both tools were developed using the Go programming language, and the bot used to distribute access keys for Webcrystal RAT closely mirrored the infrastructure employed by WebRAT.
Following criticism regarding its perceived lack of originality, the developer rebranded the malware as CrystalX RAT. This rebranding effort included establishing a dedicated Telegram channel for marketing, complete with access key giveaways and polls, and even launching a YouTube channel to demonstrate the malware’s expanding feature set and capabilities.

Unusual Feature Set and Global Reach
Analysts at Securelist conducted a detailed technical analysis of CrystalX, confirming its active deployment and noting that its feature set extends beyond typical commercial RATs. The malware is sold across three subscription tiers, providing buyers with access to a web-based control panel. This panel offers a wide array of functions, from discreet file exfiltration to live remote screen control.
A distinguishing characteristic of CrystalX is its integration of serious espionage capabilities with an entire section of “prank commands” designed for victim harassment and disruption. This unusual combination makes CrystalX a particularly noteworthy threat in the current MaaS landscape.
While infection attempts have been predominantly observed in Russia, CrystalX lacks any inherent geographic restrictions, allowing any subscriber to deploy it against targets worldwide. Kaspersky products are capable of detecting this threat under various signatures, including Backdoor.Win64.CrystalX, Trojan.Win64.Agent, and Trojan.Win32.Agentb.gen.
Ongoing development of new implant versions indicates that CrystalX is still actively being refined. As the attacker intensifies promotional efforts, the malware’s subscriber base is expected to expand, increasing its potential impact.
Detection Evasion and Anti-Analysis Tactics
CrystalX incorporates sophisticated techniques to evade detection and hinder analysis. Each malware implant is initially compressed using zlib and then encrypted with the ChaCha20 algorithm, employing a hard-coded 32-byte key and a 12-byte nonce. This encryption significantly complicates static analysis efforts.
The malware’s auto-builder, accessible through the control panel, allows operators to configure anti-analysis features during the build process. These options include selective geoblocking by country and the ability to customize executable icons, further complicating attribution and detection.
During execution, CrystalX performs a series of checks to determine if it is operating within an analysis environment. It inspects a Windows registry value to detect the presence of proxy tools like Fiddler, Burp Suite, or mitmproxy, and subsequently blacklists their process names. A separate routine is dedicated to virtual machine detection, examining running processes, installed guest tools, and hardware characteristics to confirm operation on a genuine system.
An anti-attach loop continuously monitors the debug flag, debug port, hardware breakpoints, and program execution timing to thwart any attempts at debugger attachment. Furthermore, CrystalX patches critical Windows functions such as AmsiScanBuffer, EtwEventWrite, and MiniDumpWriteDump. This action disables security instrumentation and memory dumping tools that cybersecurity analysts frequently rely on during investigations, making forensic analysis significantly more challenging.

After successfully bypassing these checks, CrystalX establishes a connection to its command-and-control (C2) server via a hard-coded WebSocket URL to begin collecting system data. Known C2 domains associated with CrystalX include webcrystal.lol, webcrystal.sbs, and crystalxrat.top.
What You Should Do
- Organizations should immediately block the known C2 domains (webcrystal.lol, webcrystal.sbs, crystalxrat.top) at their network perimeter.
- Monitor network traffic for unusual outbound WebSocket connections, which could indicate CrystalX activity.
- Investigate any executable exhibiting anti-debugging behaviors or attempts to patch critical Windows functions.
- Ensure all endpoint protection tools, including antivirus and Endpoint Detection and Response (EDR) solutions, are regularly updated with the latest threat intelligence.
- Implement robust email and web filtering to prevent initial infection vectors, as MaaS offerings often rely on phishing or malicious downloads.
- Educate users about the risks of suspicious links and attachments to prevent the download and execution of malware.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.