Researchers reported an active campaign distributing CrystalX, a malware-as-a-service (MaaS) remote access trojan sold through private Telegram channels, a dedicated Telegram presence, YouTube promotion, and a web-based control panel. The service offers subscription tiers and bundles multiple capabilities into one payload, including RAT access, credential theft, keylogging, clipboard hijacking, spyware, browser-based crypto clipping, and stealer functions, alongside unusual prankware commands designed to harass or troll victims. Analysts said the malware appears to have evolved from the earlier Webcrystal RAT, also linked to WebRAT/Salat Stealer through similarities in its Go-based code, control panel, and sales bot infrastructure.
CrystalX includes a configurable builder with geoblocking, anti-analysis, anti-debugging, and stealth patching features intended to evade detection and complicate reverse engineering. Reported defenses include zlib compression, ChaCha20 encryption, VM and debugger checks, proxy-tool detection, and patching of Windows security-related functions such as AmsiScanBuffer, EtwEventWrite, and MiniDumpWriteDump. The malware communicates with command-and-control servers over WebSocket using hard-coded URLs and exfiltrates data in plaintext JSON; observed infrastructure includes webcrystal.lol, webcrystal.sbs, and crystalxrat.top. Infection attempts have so far been observed mainly in Russia, but researchers warned the platform has no built-in regional limits and is under active development, raising the risk of broader global abuse.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-01, public reporting detailed that CrystalX combined remote access, spyware, keylogging, clipboard hijacking, browser crypto-clipping, credential stealing, and unusual prankware functions, alongside anti-analysis, anti-debugging, stealth patching, and WebSocket-based C2 communications.
During March 2026, Kaspersky observed an active campaign using CrystalX RAT, with dozens of victims and infection attempts seen in Russia. Researchers assessed the service had no built-in regional restrictions and could be used more broadly.
By March 2026, the malware operation had rebranded as CrystalX RAT and was being promoted through private Telegram chats, a dedicated Telegram channel, and YouTube as a malware-as-a-service platform sold in subscription tiers.
In January 2026, researchers believe the operation was offering a tool called Webcrystal RAT, which showed similarities to WebRAT or Salat Stealer in its control panel, Go-based codebase, and sales bot infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcesecurelist.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.