CrystalX RAT — MaaS Remote Access Trojan Combining Spyware, Stealer, Keylogger, Crypto Clipper, VNC, and Prankware
CrystalX RAT (TL-2026-0306), also tracked as Webcrystal RAT, is a high-severity malware campaign, first published 2026-04-01. It carries a reported Russia nexus and is not formally attributed, affects Microsoft Windows, maps to 25 MITRE ATT&CK techniques (T1027, T1041, T1056), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-0306
- Threat ID
- TL-2026-0306
- Also known as
- Webcrystal RAT, CrystalX
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-04-01
- Last reviewed
- 2026-04-01
- Attribution confidence
- NONE
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- individual-consumers, cryptocurrency-users, gaming-community, small-business, financial-services
- Target regions
- Russia, Eastern Europe, Global (no MaaS restrictions)
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in CrystalX RAT
Malware and tooling: Backdoor.Win64.CrystalX, Trojan.Win32.Agentb.gen, Trojan.Win64.Agent, ChromeElevator, CrystalX WebSocket Panel
CrystalX RAT is a Windows-based remote access trojan sold as malware-as-a-service (MaaS) via Telegram channels. Written in Go, it combines credential theft, keylogging, cryptocurrency clipboard hijacking, VNC remote access, and destructive prankware capabilities. It uses ChaCha20 encryption with hard-coded keys and communicates via WebSocket to C2 infrastructure.
How CrystalX RAT works
CrystalX RAT is a fully-featured Windows remote access trojan distributed through a malware-as-a-service model on Telegram. Originally marketed as Webcrystal RAT in January 2026, it was rebranded to CrystalX RAT and is actively developed with new implant versions as of March 2026.
The malware is written in Go and compiled as a 64-bit Windows executable. Each implant is compressed using zlib and encrypted with ChaCha20 using a hard-coded 32-byte key and 12-byte nonce. C2 communication occurs over WebSocket with JSON-formatted data transmission and hard-coded C2 URLs embedded in each build.
CrystalX RAT offers an extensive feature set across multiple attack categories:
**Credential Theft:** The RAT extracts credentials from Steam, Discord, and Telegram. For Chromium-based browsers, it deploys the ChromeElevator utility (dropped to %TEMP%\svc[rndInt].exe) to harvest stored passwords and cookies. Separate proprietary implementations handle Yandex and Opera browsers using base decryption routines. Collected data is staged in %TEMP%\co[rndInt] directories before exfiltration.
**Browser Extension Injection:** CrystalX leverages the Chrome DevTools Protocol (CDP) to inject malicious browser extensions into Chrome and Edge. The malicious extension is stored in %LOCALAPPDATA%\Microsoft\Edge\ExtSvc and enables real-time interception of browser activity.
**Keylogging and Clipboard Manipulation:** All user keystrokes are captured and instantly transmitted via WebSocket to the C2 server. The RAT reads and modifies clipboard contents, enabling the cryptocurrency clipper functionality that targets Bitcoin, Litecoin, Monero, Avalanche, and Dogecoin wallet addresses.
**VNC Remote Access:** Full remote desktop control including screen viewing, file upload/download, command execution via cmd.exe, file system browsing across all drives, audio/video capture from microphone and camera, and the ability to block user input during remote sessions.
**Prankware (Rofl Panel):** A distinctive feature is the prankware panel enabling desktop background manipulation, screen rotation (90/180/270 degrees), system shutdown, mouse button remapping, monitor disconnection, custom notification windows, cursor disruption, taskbar/task manager/cmd.exe disabling, desktop icon hiding, and bidirectional chat with the victim.
**Anti-Analysis and Evasion:** The malware implements comprehensive evasion including MITM detection (proxy checking via registry, blacklisting Fiddler/Burp Suite/mitmproxy processes, installed certificate verification), VM detection (process checking, guest tools detection, hardware characteristics analysis), anti-debugging (debug flag monitoring, debug port checking, hardware breakpoint detection, execution timing analysis), and stealth patches for AmsiScanBuffer, EtwEventWrite, and MiniDumpWriteDump.
**Builder Configuration:** Operators can configure selective geoblocking by country, customize executable icons, set stealer intervals (one-time or recurring), and toggle optional anti-analysis features.
While initially observed targeting systems in Russia, the MaaS platform itself has no regional restrictions, indicating potential for global targeting. The malware was previously confused with the WebRAT/Salat Stealer family due to similar panel layouts, but Kaspersky analysis confirms CrystalX is a distinct malware family with its own codebase and C2 infrastructure.
MITRE ATT&CK techniques used in TL-2026-0306
defense-evasion
T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion; T1622 Debugger Evasion
exfiltration
T1041 Exfiltration Over C2 Channel
collection
T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture; T1125 Video Capture
discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1219 Remote Access Tools; T1573 Encrypted Channel
persistence
T1176 Software Extensions; T1547 Boot or Logon Autostart Execution
impact
T1529 System Shutdown/Reboot; T1565 Data Manipulation
credential-access
T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
initial-access
defense-impairment
Affected products and versions in CrystalX RAT
- Microsoft — Windows
Vulnerable versions: 10; 11; Server 2016; Server 2019; Server 2022 - Google — Chrome
Vulnerable versions: All versions (credential theft target) - Microsoft — Edge
Vulnerable versions: All Chromium-based versions (extension injection target) - Valve — Steam
Vulnerable versions: All versions (credential theft target) - Discord — Discord Desktop
Vulnerable versions: All versions (credential theft target) - Telegram — Telegram Desktop
Vulnerable versions: All versions (credential theft target)
Remediation for CrystalX RAT
Immediate actions
- Block C2 domains webcrystal.lol, webcrystal.sbs, crystalxrat.top at DNS and proxy layers
- Hunt for WebSocket connections to known CrystalX C2 infrastructure
- Scan endpoints for ChromeElevator utility drops in %TEMP%\svc*.exe
- Check for malicious browser extensions in %LOCALAPPDATA%\Microsoft\Edge\ExtSvc
- Monitor for AmsiScanBuffer and EtwEventWrite patching attempts
Workarounds
- Restrict execution of unsigned Go binaries via application control policies
- Block WebSocket connections to unknown external hosts at network perimeter
- Enable Windows Credential Guard to protect browser credential stores
- Disable Chrome DevTools Protocol in managed browser deployments
Longer-term hardening
- Deploy EDR with behavioral detection for in-memory AMSI/ETW patching
- Implement application whitelisting to prevent unauthorized Go binaries
- Enable browser extension management policies to block sideloaded extensions
- Monitor for Chrome DevTools Protocol abuse on endpoints
- Implement clipboard monitoring for cryptocurrency address substitution patterns
- Deploy network detection for WebSocket-based C2 communication patterns
Timeline of CrystalX RAT
- CrystalX RAT first mentioned in private Telegram chats under original name Webcrystal RAT
- Dedicated Telegram channel created for CrystalX marketing with promotional videos on YouTube
- Malware rebranded from Webcrystal RAT to CrystalX RAT with updated panel and features
- Three subscription tiers launched with access key distribution via Telegram bot, marketing draws and polls for customer acquisition
- First confirmed infection attempts observed targeting systems in Russia
- Kaspersky DFIR team begins investigation into CrystalX RAT samples recovered from incident response engagement
- Active development confirmed with new implant versions featuring updated evasion capabilities
- Kaspersky Securelist publishes comprehensive technical analysis of CrystalX RAT
- As of 2026-05-29, CrystalX RAT remains a live MaaS threat: fresh samples were submitted May 1 and May 11, 2026 hitting active C2 (crystalxrat.net, registered Apr 14 with a TLS cert valid through Jul 13), still sold via Telegram. No takedown, sinkhole, or arrests reported, and analysts expect infections to rise.
Sources cited for CrystalX RAT
- Kaspersky Securelist: A Laughing RAT — CrystalX Combines Spyware, Stealer, and Prankware Features
- CYFIRMA: Unmasked Salat Stealer — Deep Dive into Persistence and C2 Infrastructure (Related MaaS Family)
- ANY.RUN: SalatStealer Malware Analysis (Related MaaS Family)
- Malpedia: SalatStealer (Related MaaS Family)
- MITRE ATT&CK: Clipboard Data (T1115)
- MITRE ATT&CK: Input Capture — Keylogging (T1056.001)
Threats related to CrystalX RAT
- Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)
- Remus Stealer: 64-bit Lumma-Derived Infostealer-as-a-Service with EtherHiding Blockchain C2 and Application-Bound Encryption Bypass
- GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine: LegionRelay/PhantomRelay PowerShell RATs & FallSpy Android Spyware (WithSecure)
Detection coverage for TL-2026-0306
As of 2026-04-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0306 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.