CrystalX RAT — MaaS Remote Access Trojan Combining Spyware, Stealer, Keylogger, Crypto Clipper, VNC, and Prankware — Threadlinqs Intelligence
As of 2026-05-30, CrystalX RAT — MaaS Remote Access Trojan Combining Spyware, Stealer, Keylogger, Crypto Clipper, VNC, and Prankware is a high-severity malware threat attributed to a Russia-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0306 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Russia · FINANCIAL
CrystalX RAT is a Windows-based remote access trojan sold as malware-as-a-service (MaaS) via Telegram channels. Written in Go, it combines credential theft, keylogging, cryptocurrency clipboard
CrystalX RAT is a fully-featured Windows remote access trojan distributed through a malware-as-a-service model on Telegram. Originally marketed as Webcrystal RAT in January 2026, it was rebranded to CrystalX RAT and is actively developed with new implant versions as of March 2026.
The malware is written in Go and compiled as a 64-bit Windows executable. Each implant is compressed using zlib and encrypted with ChaCha20 using a hard-coded 32-byte key and 12-byte nonce. C2 communication occurs over WebSocket with JSON-formatted data transmission and hard-coded C2 URLs embedded in each build.
CrystalX RAT offers an extensive feature set across multiple attack categories:
**Credential Theft:** The RAT extracts credentials from Steam, Discord, and Telegram. For Chromium-based browsers, it deploys the ChromeElevator utility (dropped to %TEMP%\svc[rndInt].exe) to harvest stored passwords and cookies. Separate proprietary implementations handle Yandex and Opera browsers using base decryption routines. Collected data is staged in %TEMP%\co[rndInt] directories before exfiltration.
**Browser Extension Injection:** CrystalX leverages the Chrome DevTools Protocol (CDP) to inject malicious browser extensions into Chrome and Edge. The malicious extension is stored in %LOCALAPPDATA%\Microsoft\Edge\ExtSvc and enables real-time interception of browser activity.
**Keylogging and Clipboard Manipulation:** All user keystrokes are captured and instantly transmitted via WebSocket to the C2 server. The RAT reads and modifies clipboard contents, enabling the cryptocurrency clipper functionality that targets Bitcoin, Litecoin, Monero, Avalanche, and Dogecoin wallet addresses.
**VNC Remote Access:** Full remote desktop control including screen viewing, file upload/download, command execution via cmd.exe, file system browsing across all drives, audio/video capture from microphone and camera, and the ability to block user input during remote sessions.
**Prankware (Rofl Panel):** A distinctive feature is the prankware panel enabling desktop background manipulation, screen rotation (90/180/270 degrees), system shutdown, mouse button remapping, monitor disconnection, custom notification windows, cursor disruption, taskbar/task manager/cmd.exe disabling, desktop icon hiding, and bidirectional chat with the victim.
**Anti-Analysis and Evasion:** The malware implements comprehensive evasion including MITM detection (proxy checking via registry, blacklisting Fiddler/Burp Suite/mitmproxy processes, installed certificate verification), VM detection (process checking, guest tools detection, hardware characteristics analysis), anti-debugging (debug flag monitoring, debug port checking, hardware breakpoint detection, execution timing analysis), and stealth patches for AmsiScanBuffer, EtwEventWrite, and MiniDumpWriteDump.
**Builder Configuration:** Operators can configure selective geoblocking by country, customize executable icons, set stealer intervals (one-time or recurring), and toggle optional anti-analysis features.
While initially observed targeting systems in Russia, the MaaS platform itself has no regional restrictions, indicating potential for global targeting. The malware was previously confused with the WebRAT/Salat Stealer family due to similar panel layouts, but Kaspersky analysis confirms CrystalX is a distinct malware family with its own codebase and C2 infrastructure.
Target sectors: individual-consumers, cryptocurrency-users, gaming-community, small-business, financial-services
Target regions: Russia, Eastern Europe, Global (no MaaS restrictions)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1059, T1204, T1547, T1176, T1562, T1027, T1497, T1622, T1555