Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

CrystalX RAT: Malware‑as‑a‑Service Enables Spyware, Credential Theft, and Full Remote Access

Kaspersky reports a new RAT offered as a subscription service that bundles spyware, credential stealing, and remote‑control functions. Its modular builder, anti‑analysis tricks, and encrypted C2 channel make it a potent threat to any organization that allows third‑party remote access.

LiveThreat™ Intelligence · 📅 April 04, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

CrystalX RAT: Malware‑as‑a‑Service Combines Spyware, Credential Stealer, and Full Remote Access

What Happened — Kaspersky uncovered a new RAT sold as a Malware‑as‑a‑Service (MaaS) on Telegram and YouTube. The “CrystalX” platform lets attackers purchase a customizable remote‑access trojan that includes keylogging, clipboard hijacking, crypto‑wallet address swapping, and data‑stealing modules for browsers and gaming apps.

Why It Matters for TPRM —

  • The service’s subscription model lowers the barrier for low‑skill actors to launch sophisticated espionage campaigns against third‑party vendors.
  • Built‑in anti‑analysis and encrypted communications make detection difficult, increasing the risk of prolonged, undetected compromise of partner environments.
  • Credential‑stealing capabilities target widely used services (Steam, Discord, Chromium browsers), potentially exposing shared accounts and API keys used in supply‑chain integrations.

Who Is Affected — All sectors that rely on Windows workstations, especially SaaS providers, MSPs, and organizations that store crypto‑wallet credentials or use popular browsers for SSO.

Recommended Actions —

  • Review any third‑party relationships that provide remote‑desktop or support tools; verify they enforce strict endpoint hardening.
  • Deploy behavior‑based EDR capable of detecting anomalous WebSocket C2 traffic and ChaCha20‑encrypted payloads.
  • Enforce least‑privilege for credential storage; rotate service‑account passwords regularly.

Technical Notes — The RAT uses a hard‑coded WebSocket C2 URL, compresses payloads with zlib, encrypts with ChaCha20, and employs anti‑debugging (VM detection, proxy checks). Data exfiltration is sent as plain‑text JSON; the stealer module currently targets Steam, Discord, Telegram, and Chromium‑based browsers via the ChromeElevator utility. Remote‑access features include VNC screen control, audio/video capture, and a “prank” module that can alter user UI. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/190310/cyber-crime/crystalx-rat-new-maas-malware-combines-spyware-stealer-and-remote-access.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →