A laughing RAT: CrystalX combines spyware, stealer, and prankware features
In March 2026 researchers uncovered an active MaaS campaign promoting CrystalX (initially marketed as Webcrystal/WebRAT) via private Telegram chats and a YouTube channel; the RAT offers a builder and a wide feature set including stealer, keylogger, clipper, remote access, spyware, and extensive prankware. Kaspersky detects it as Backdoor.Win64.CrystalX.*, Trojan.Win64.Agent.*, and Trojan.Win32.Agentb.gen, telemetry shows active development and dozens of victims so far. #CrystalXRAT #Webcrystal
March 2026 reveals CrystalX, a versatile RAT combining spyware, stealer, keylogger, clipper, remote access, and prankware features. Distributed via Telegram and YouTube with multiple subscription tiers. #CrystalXRAT #MalwareTrends #Russia