CrystalRAT is a malware-as-a-service (MaaS) remote access trojan promoted on Telegram and YouTube. Reporting cited in the content states it emerged in January and is sold via a tiered subscription model. Its capabilities include remote access, data theft, keylogging, clipboard hijacking, and a notable set of prankware/disruption features. Kaspersky assessed that it shares significant similarities with WebRAT, also known as Salat Stealer, including a similar panel design, Go-based implementation, and bot-driven sales model. The malware includes a user-friendly control panel and an automated payload builder with customization options such as geoblocking, executable customization, and anti-analysis features including anti-debugging, virtual machine detection, and proxy detection. The content also states payloads are compressed with zlib, encrypted with ChaCha20, and communicate with command-and-control infrastructure over WebSocket.
CrystalRAT targets Chromium-based browsers as well as Yandex and Opera, and steals data from desktop applications including Steam, Discord, and Telegram. One report notes its infostealer component was temporarily disabled while being upgraded. Its remote access functionality supports command execution, file upload/download, file browsing, and real-time control via built-in VNC. Additional surveillance and theft capabilities mentioned in the content include microphone/audio capture, video capture, real-time keylogging, and a clipper that detects cryptocurrency wallet addresses in the clipboard and replaces them with attacker-controlled addresses.
Its prankware features include changing wallpaper, altering display orientation, forcing shutdowns, remapping mouse buttons, disabling input devices, showing fake notifications, moving the cursor, hiding desktop components, and providing an attacker-victim chat window. The content notes these features may be intended to attract low-skilled threat actors or distract victims while theft occurs in the background. No specific threat actor attribution beyond the MaaS operation itself is provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The generated payloads are zlib-compressed and encrypted with the ChaCha20 symmetric stream cipher for protection.
It features a user-friendly control panel and an automated builder that allows customization of payloads, including geoblocking and anti-analysis techniques.
The malware connects to the command-and-control (C2) via WebSocket and sends info about the host for profiling and infection tracking.
Its remote access module enables command execution, file transfer, and real-time control via VNC.
It features a user-friendly control panel and an automated builder that allows customization of payloads, including geoblocking and anti-analysis techniques.
the malware provides a user-friendly control panel and an automated builder tool that supports customization options, including geoblocking, executable customization, and anti-analysis features (anti-debugging, VM detection, proxy detection, etc.)
The malware targets Chromium-based browsers, Yandex, and Opera, and also collects data from desktop applications like Steam, Discord, and Telegram.
This MaaS offers a range of malicious capabilities, including remote access, data theft, keylogging, and clipboard hijacking...
This MaaS offers a range of malicious capabilities, including remote access, data theft, keylogging, and clipboard hijacking...
The malware connects to the command-and-control (C2) via WebSocket and sends info about the host for profiling and infection tracking.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware-as-a-service offering remote access, data theft, keylogging, clipboard hijacking, browser and application data theft, command execution, file transfer, and real-time VNC control. It also includes prankware features such as changing wallpaper, altering display orientation, forcing shutdowns, and disabling input devices.
CrystalRAT is a malware-as-a-service remote access trojan with data theft, keylogging, clipboard hijacking, file management, command execution, VNC-based remote control, audio/video capture, and prankware capabilities. It includes an infostealer component targeting Chromium-based browsers, Yandex, Opera, and desktop apps such as Steam, Discord, and Telegram.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.