Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Indicator Value Persistence path %LOCALAPPDATA%\Microsoft\DeviceMetadataStore\SecurityHealthSystray.exe Scheduled task prefix NvContainerTask_
VM registry keys VMware Tools, VirtualBox Guest Additions, VBoxGuest/Mouse/Service, vmci, vmhgfs
Indicator Value Persistence path %LOCALAPPDATA%\Microsoft\DeviceMetadataStore\SecurityHealthSystray.exe Scheduled task prefix NvContainerTask_
The Go payload encrypts all its strings... takes the first 12 bytes as an AES-GCM nonce, and decrypts the rest with a static key... The Go binary is also obfuscated at the type level. Package paths are renamed to random 8-12 character identifiers.
Persistence path %LOCALAPPDATA%\Microsoft\DeviceMetadataStore\SecurityHealthSystray.exe Scheduled task prefix NvContainerTask_
If checks pass, the payload runs PowerShell commands to disable Defender and Sysmon, purge event logs with wevtutil
Resource ID 970 holds the encrypted Go payload through three operations... XOR ... ChaCha20 ... Raw DEFLATE ... The result is a PE32+ x64 Go executable.
Defender gets exclusions for C:\Windows\System32\svchost.exe and the entire System32 directory.
Indicator Value ... Mutex prefix Global\WinSecMutex_ Lock file suffix .lock
A separate virtual machine detection routine examines running processes, installed guest tools, and hardware characteristics to confirm it is indeed running on a real system.
The Go payload checks its environment across several categories before C2 activity: MAC prefixes ... Hostnames sandbox, malware, virus, analysis ... Users sandbox ... VM registry keys ... VM processes ... Analysis tools wireshark, procmon ...
Users sandbox, virus, malware, maltest, test, john, user, currentuser
VM processes VBoxService, vmtoolsd, prl_tools, qemu-ga, xenservice Analysis tools wireshark, procmon, processhacker, x64dbg, ollydbg, ida, windbg, dnSpy, fiddler, burp
System Screenshot ( BitBlt ), hardware info, IP geolocation, installed software, startup entries
A separate virtual machine detection routine examines running processes, installed guest tools, and hardware characteristics to confirm it is indeed running on a real system.
Resource 970 unwraps into a Go payload that uses a WebSocket path... Type Value Context Domain crystalxrat[.]net:443 Primary C2 URL path /api/ws WebSocket endpoint
CrystalX is delivered as a compact native x64 loader with a large RCDATA resource. Resource 970 unwraps into a Go payload.
Additionally, the malware patches critical Windows functions, including AmsiScanBuffer, EtwEventWrite, and MiniDumpWriteDump, disabling security instrumentation and memory dumping tools that analysts regularly rely on during investigations.
If checks pass, the payload runs PowerShell commands to disable Defender and Sysmon, purge event logs with wevtutil , and harden ACLs on its installation directory. Event logs for TaskScheduler and Services are disabled. Inbound firewall notification is turned off.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage malware family consisting of a loader that decrypts and manually maps a Go-based RAT payload. The payload uses AES-GCM-obfuscated strings, communicates over TLS WebSocket C2, supports remote desktop, webcam, shell execution, file management, persistence, anti-analysis, and broad credential/data theft from browsers, crypto wallets, Discord, Telegram, Steam, and Roblox.
A MaaS platform marketed via private Telegram channels that provides remote access, credential theft, keylogging, clipboard hijacking, spyware capabilities, file exfiltration, live remote screen control, prankware functions, and multiple anti-analysis and evasion features including ChaCha20-encrypted implants, VM detection, anti-debugging, and patching of AMSI/ETW/MiniDump-related functions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.