CrystalX RAT — MaaS Remote Access Trojan Combining Spyware, Stealer, Keylogger, Crypto Clipper, VNC, and Prankware

CrystalX RAT (TL-2026-0306), also tracked as Webcrystal RAT, is a high-severity malware campaign, first published 2026-04-01. It carries a reported Russia nexus and is not formally attributed, affects Microsoft Windows, maps to 25 MITRE ATT&CK techniques (T1027, T1041, T1056), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-0306

Threat ID
TL-2026-0306
Also known as
Webcrystal RAT, CrystalX
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-04-01
Last reviewed
2026-04-01
Attribution confidence
NONE
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
individual-consumers, cryptocurrency-users, gaming-community, small-business, financial-services
Target regions
Russia, Eastern Europe, Global (no MaaS restrictions)
Detection rules
9
Indicators of compromise
24

Malware and tooling in CrystalX RAT

Malware and tooling: Backdoor.Win64.CrystalX, Trojan.Win32.Agentb.gen, Trojan.Win64.Agent, ChromeElevator, CrystalX WebSocket Panel

CrystalX RAT is a Windows-based remote access trojan sold as malware-as-a-service (MaaS) via Telegram channels. Written in Go, it combines credential theft, keylogging, cryptocurrency clipboard hijacking, VNC remote access, and destructive prankware capabilities. It uses ChaCha20 encryption with hard-coded keys and communicates via WebSocket to C2 infrastructure.

How CrystalX RAT works

CrystalX RAT is a fully-featured Windows remote access trojan distributed through a malware-as-a-service model on Telegram. Originally marketed as Webcrystal RAT in January 2026, it was rebranded to CrystalX RAT and is actively developed with new implant versions as of March 2026.

The malware is written in Go and compiled as a 64-bit Windows executable. Each implant is compressed using zlib and encrypted with ChaCha20 using a hard-coded 32-byte key and 12-byte nonce. C2 communication occurs over WebSocket with JSON-formatted data transmission and hard-coded C2 URLs embedded in each build.

CrystalX RAT offers an extensive feature set across multiple attack categories:

**Credential Theft:** The RAT extracts credentials from Steam, Discord, and Telegram. For Chromium-based browsers, it deploys the ChromeElevator utility (dropped to %TEMP%\svc[rndInt].exe) to harvest stored passwords and cookies. Separate proprietary implementations handle Yandex and Opera browsers using base decryption routines. Collected data is staged in %TEMP%\co[rndInt] directories before exfiltration.

**Browser Extension Injection:** CrystalX leverages the Chrome DevTools Protocol (CDP) to inject malicious browser extensions into Chrome and Edge. The malicious extension is stored in %LOCALAPPDATA%\Microsoft\Edge\ExtSvc and enables real-time interception of browser activity.

**Keylogging and Clipboard Manipulation:** All user keystrokes are captured and instantly transmitted via WebSocket to the C2 server. The RAT reads and modifies clipboard contents, enabling the cryptocurrency clipper functionality that targets Bitcoin, Litecoin, Monero, Avalanche, and Dogecoin wallet addresses.

**VNC Remote Access:** Full remote desktop control including screen viewing, file upload/download, command execution via cmd.exe, file system browsing across all drives, audio/video capture from microphone and camera, and the ability to block user input during remote sessions.

**Prankware (Rofl Panel):** A distinctive feature is the prankware panel enabling desktop background manipulation, screen rotation (90/180/270 degrees), system shutdown, mouse button remapping, monitor disconnection, custom notification windows, cursor disruption, taskbar/task manager/cmd.exe disabling, desktop icon hiding, and bidirectional chat with the victim.

**Anti-Analysis and Evasion:** The malware implements comprehensive evasion including MITM detection (proxy checking via registry, blacklisting Fiddler/Burp Suite/mitmproxy processes, installed certificate verification), VM detection (process checking, guest tools detection, hardware characteristics analysis), anti-debugging (debug flag monitoring, debug port checking, hardware breakpoint detection, execution timing analysis), and stealth patches for AmsiScanBuffer, EtwEventWrite, and MiniDumpWriteDump.

**Builder Configuration:** Operators can configure selective geoblocking by country, customize executable icons, set stealer intervals (one-time or recurring), and toggle optional anti-analysis features.

While initially observed targeting systems in Russia, the MaaS platform itself has no regional restrictions, indicating potential for global targeting. The malware was previously confused with the WebRAT/Salat Stealer family due to similar panel layouts, but Kaspersky analysis confirms CrystalX is a distinct malware family with its own codebase and C2 infrastructure.

MITRE ATT&CK techniques used in TL-2026-0306

defense-evasion

T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion; T1622 Debugger Evasion

exfiltration

T1041 Exfiltration Over C2 Channel

collection

T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture; T1125 Video Capture

discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1219 Remote Access Tools; T1573 Encrypted Channel

persistence

T1176 Software Extensions; T1547 Boot or Logon Autostart Execution

impact

T1529 System Shutdown/Reboot; T1565 Data Manipulation

credential-access

T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

initial-access

T1566 Phishing

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CrystalX RAT

  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2016; Server 2019; Server 2022
  • Google — Chrome
    Vulnerable versions: All versions (credential theft target)
  • Microsoft — Edge
    Vulnerable versions: All Chromium-based versions (extension injection target)
  • Valve — Steam
    Vulnerable versions: All versions (credential theft target)
  • Discord — Discord Desktop
    Vulnerable versions: All versions (credential theft target)
  • Telegram — Telegram Desktop
    Vulnerable versions: All versions (credential theft target)

Remediation for CrystalX RAT

Immediate actions

  • Block C2 domains webcrystal.lol, webcrystal.sbs, crystalxrat.top at DNS and proxy layers
  • Hunt for WebSocket connections to known CrystalX C2 infrastructure
  • Scan endpoints for ChromeElevator utility drops in %TEMP%\svc*.exe
  • Check for malicious browser extensions in %LOCALAPPDATA%\Microsoft\Edge\ExtSvc
  • Monitor for AmsiScanBuffer and EtwEventWrite patching attempts

Workarounds

  • Restrict execution of unsigned Go binaries via application control policies
  • Block WebSocket connections to unknown external hosts at network perimeter
  • Enable Windows Credential Guard to protect browser credential stores
  • Disable Chrome DevTools Protocol in managed browser deployments

Longer-term hardening

  • Deploy EDR with behavioral detection for in-memory AMSI/ETW patching
  • Implement application whitelisting to prevent unauthorized Go binaries
  • Enable browser extension management policies to block sideloaded extensions
  • Monitor for Chrome DevTools Protocol abuse on endpoints
  • Implement clipboard monitoring for cryptocurrency address substitution patterns
  • Deploy network detection for WebSocket-based C2 communication patterns

Timeline of CrystalX RAT

  • CrystalX RAT first mentioned in private Telegram chats under original name Webcrystal RAT
  • Dedicated Telegram channel created for CrystalX marketing with promotional videos on YouTube
  • Malware rebranded from Webcrystal RAT to CrystalX RAT with updated panel and features
  • Three subscription tiers launched with access key distribution via Telegram bot, marketing draws and polls for customer acquisition
  • First confirmed infection attempts observed targeting systems in Russia
  • Kaspersky DFIR team begins investigation into CrystalX RAT samples recovered from incident response engagement
  • Active development confirmed with new implant versions featuring updated evasion capabilities
  • Kaspersky Securelist publishes comprehensive technical analysis of CrystalX RAT
  • As of 2026-05-29, CrystalX RAT remains a live MaaS threat: fresh samples were submitted May 1 and May 11, 2026 hitting active C2 (crystalxrat.net, registered Apr 14 with a TLS cert valid through Jul 13), still sold via Telegram. No takedown, sinkhole, or arrests reported, and analysts expect infections to rise.

Sources cited for CrystalX RAT

Threats related to CrystalX RAT

Detection coverage for TL-2026-0306

As of 2026-04-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0306 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats