Malware · 166 days ago
Kaspersky found a new MaaS called CrystalX that sells ready-made RAT implants to third-party operators. The service is offered in three subscription tiers and provides a web panel, C2 domains, and sample hashes. The builder creates Go-based binaries with anti-debugging, geoblocking, and many configuration options. Deployed payloads combine a remote access backdoor with a stealer, keylogger, clipboard clipper, and a catalog of prankware features. The operator-facing panel and marketing on Telegram and YouTube let low-skill buyers assemble campaigns quickly.
3 sources covering this story
Sophisticated CrystalX RAT Emerges
The malware can spy on victims, steal their information, and make configuration changes on devices.
New CrystalRAT malware adds RAT, stealer and prankware features
A new malware-as-a-service called CrystalRAT is being promoted on Telegram, offering remote access, data theft, keylogging, and clipboard hijacking capabilities.
An analysis of CrystalX commercial RAT with prankware features
Kaspersky researchers analyze a new CrystalX RAT distributed as MaaS and featuring extensive spyware, stealer, and prankware capabilities.
Part of the PlainSec briefing for 2026-04-02