{"id":2236,"date":"2026-04-01T06:04:59","date_gmt":"2026-04-01T06:04:59","guid":{"rendered":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/"},"modified":"2026-04-01T06:04:59","modified_gmt":"2026-04-01T06:04:59","slug":"a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features","status":"publish","type":"post","link":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/","title":{"rendered":"A laughing RAT: CrystalX combines spyware, stealer, and prankware features"},"content":{"rendered":"<div>\n<p><img width=\"990\" height=\"400\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg\" class=\"attachment-securelist-huge-promo size-securelist-huge-promo wp-post-image\" alt=\"\" decoding=\"async\" loading=\"lazy\"><\/p>\n<h2 id=\"introduction\">Introduction<\/h2>\n<p>In March\u202f2026, we discovered an active campaign promoting previously unknown malware in private Telegram chats. The Trojan was offered as a MaaS (malware\u2011as\u2011a\u2011service) with three subscription tiers. It caught our attention because of its extensive arsenal of capabilities. On the panel provided to third\u2011party actors, in addition to the standard features of RAT\u2011like malware, a stealer, keylogger, clipper, and spyware are also available. Most surprisingly, it also includes prankware capabilities: a large set of features designed to trick, annoy, and troll the user. Such a combination of capabilities makes it a rather unique Trojan in its category.<\/p>\n<p>Kaspersky\u2019s products detect this threat as Backdoor.Win64.CrystalX.*, Trojan.Win64.Agent.*, Trojan.Win32.Agentb.gen.<\/p>\n<h2 id=\"technical-details\">Technical details<\/h2>\n<h3 id=\"background\">Background<\/h3>\n<p>The new malware was first mentioned in January\u202f2026 in a private Telegram chat for developers of RAT malware. The author actively promoted their creation, called Webcrystal RAT, by attaching screenshots of the web panel. Many users observed that the panel layout was identical to that of the previously known <a href=\"https:\/\/securelist.com\/webrat-distributed-via-github\/118555\/\" target=\"_blank\">WebRAT<\/a> (also called Salat\u202fStealer), leading them to label this malware as a copy. Additional similarities included the fact that the RAT was written in Go, and the messages from the bot selling access keys to the control panel closely matched those of the WebRAT bots.<\/p>\n<p><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100755\/crystalx-rat1.png\" class=\"magnificImage\"><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-119285\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100755\/crystalx-rat1.png\" alt=\"\" width=\"1219\" height=\"601\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100755\/crystalx-rat1.png 1219w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100755\/crystalx-rat1-300x148.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100755\/crystalx-rat1-1024x505.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100755\/crystalx-rat1-768x379.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100755\/crystalx-rat1-710x350.png 710w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100755\/crystalx-rat1-740x365.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100755\/crystalx-rat1-568x280.png 568w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100755\/crystalx-rat1-800x394.png 800w\" sizes=\"(max-width: 1219px) 100vw, 1219px\"><\/a><\/p>\n<p>After some time, this malware was rebranded and received a new name, CrystalX RAT. Its promotion moved to a corresponding new channel, which is quite busy and features marketing tricks, such as access key draws and polls. Moreover, it expanded beyond Telegram: a special YouTube channel was created, aimed at marketing promotion and already containing a video review of the capabilities of this malware.<\/p>\n<p><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100847\/crystalx-rat2.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-119286\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100847\/crystalx-rat2.png\" alt=\"\" width=\"1180\" height=\"908\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100847\/crystalx-rat2.png 1180w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100847\/crystalx-rat2-300x231.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100847\/crystalx-rat2-1024x788.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100847\/crystalx-rat2-768x591.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100847\/crystalx-rat2-455x350.png 455w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100847\/crystalx-rat2-740x569.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100847\/crystalx-rat2-364x280.png 364w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31100847\/crystalx-rat2-800x616.png 800w\" sizes=\"auto, (max-width: 1180px) 100vw, 1180px\"><\/a><\/p>\n<h3 id=\"the-builder-and-anti-debug-features\">The builder and anti-debug features<\/h3>\n<p>By default, the malware control panel provides third parties with an auto\u2011builder featuring a wide range of configurations, such as selective geoblocking by country, anti\u2011analysis functions, an executable icon, and others. Each implant is compressed using\u202fzlib and then encrypted with ChaCha20 and a hard\u2011coded 32\u2011byte key with a 12\u2011byte nonce. The malware has basic anti\u2011debugging functionality combined with additional optional capabilities:<\/p>\n<ul>\n<li><strong>MITM Check<\/strong>: checking if a proxy is enabled by reading the registry value <code>HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings<\/code>, blacklisting names of certain processes (Fiddler, Burp Suite, mitmproxy, etc.), and verifying the presence of installed certificates for the corresponding programs<\/li>\n<li><strong>VM detect<\/strong>: checking running processes, presence of guest tools, and hardware characteristics<\/li>\n<li><strong>Anti-attach loop:<\/strong> an infinite loop checking the debug flag, debug port, hardware breakpoints, and program execution timings<\/li>\n<li><strong>Stealth patches<\/strong>: patches for functions such as <code>AmsiScanBuffer<\/code>, <code>EtwEventWrite<\/code>, <code>MiniDumpWriteDump<\/code><\/li>\n<\/ul>\n<h3><strong>Stealer capabilities<\/strong><\/h3>\n<p>When launched, the malware establishes a connection to its C2 using a hard\u2011coded URL over the WebSocket protocol. It performs an initial collection of system information, after which all data is sent in JSON format as plain text. Then the malware executes the stealer function, doing so either once or at predefined intervals depending on the build options. The stealer extracts the victim\u2019s credentials for Steam, Discord, and Telegram from the system. It also gathers data from Chromium\u2011based browsers using the popular <strong>ChromeElevator<\/strong> utility. To do this, it decodes and decompresses the utility using base64\u202fand\u202fgunzip and saves it to <code>%TEMP%svc[rndInt].exe<\/code>, then creates a directory <code>%TEMP%co[rndInt]<\/code>, where the collected data is stored, and finally runs ChromeElevator with all available options.<\/p>\n<p><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101158\/crystalx-rat3.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-119287\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101158\/crystalx-rat3.png\" alt=\"\" width=\"747\" height=\"543\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101158\/crystalx-rat3.png 747w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101158\/crystalx-rat3-300x218.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101158\/crystalx-rat3-481x350.png 481w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101158\/crystalx-rat3-740x538.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101158\/crystalx-rat3-385x280.png 385w\" sizes=\"auto, (max-width: 747px) 100vw, 747px\"><\/a><\/p>\n<p>The collected data is exfiltrated to the C2. For Yandex and Opera browsers, the stealer has a separate proprietary implementation with base decryption directly on the victim\u2019s system. Notably, the builds created at the time the article was written lack the stealer functionality. OSINT results show that the author intentionally removed it with the aim to update the stealer arsenal before enabling it again.<\/p>\n<h3 id=\"keylogger-clipper\">Keylogger &amp; clipper<\/h3>\n<p>Another option of the RAT is the keylogger. All user input is instantly transmitted via WebSocket to the C2, where it is assembled into a coherent text suitable for analysis. Additionally, the malware allows the attacker to read and modify the victim\u2019s clipboard by issuing appropriate commands from the control panel. Moreover, it can inject a malicious clipper into the Chrome or Edge browser. This happens according to the following algorithm:<\/p>\n<ol>\n<li>The special malware command <code>clipper:set:[ADDR1,...]<\/code> with the attackers\u2019 crypto\u2011wallets addresses passed as arguments launches the clipper injection thread.<\/li>\n<li>A <code>%LOCALAPPDATA%MicrosoftEdgeExtSvc<\/code> directory is created (regardless whether Edge or Chrome is the target of the injection), in which a malicious extension is stored, consisting of a manifest and a single JS script named <code>content.js<\/code>.<\/li>\n<li>The <code>content.js<\/code> script is dynamically generated, containing regular expressions for crypto wallet addresses (such as Bitcoin, Litecoin, Monero, Avalanche, Doge, and others) and substitution values.<\/li>\n<li>The generated script is activated via the Chrome DevTools (CDP) protocol using the command <code>Page.addScriptToEvaluateOnNewDocument<\/code>.<\/li>\n<\/ol>\n<p>The final script looks as follows:<\/p>\n<p><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101407\/crystalx-rat4.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-119288\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101407\/crystalx-rat4.png\" alt=\"\" width=\"1069\" height=\"736\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101407\/crystalx-rat4.png 1069w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101407\/crystalx-rat4-300x207.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101407\/crystalx-rat4-1024x705.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101407\/crystalx-rat4-768x529.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101407\/crystalx-rat4-508x350.png 508w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101407\/crystalx-rat4-740x509.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101407\/crystalx-rat4-407x280.png 407w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31101407\/crystalx-rat4-800x551.png 800w\" sizes=\"auto, (max-width: 1069px) 100vw, 1069px\"><\/a><\/p>\n<h3 id=\"remote-access\">Remote access<\/h3>\n<p>The malware has a large set of commands for remote access to the victim\u2019s system. The attacker can upload arbitrary files, execute any commands using <code>cmd.exe<\/code>, and also browse the file system, including all available drives. Moreover, the RAT includes its own VNC that allows the attacker to view the victim\u2019s screen and control it remotely. Since both the attacker and the victim use the same session, the panel provides a number of buttons to block user input so that the attacker can perform necessary actions unhindered. The malware can also capture the audio stream from the microphone and the video stream from the camera in the background.<\/p>\n<p><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102059\/crystalx-rat5.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-119289\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102059\/crystalx-rat5.png\" alt=\"\" width=\"1360\" height=\"1046\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102059\/crystalx-rat5.png 1360w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102059\/crystalx-rat5-300x231.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102059\/crystalx-rat5-1024x788.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102059\/crystalx-rat5-768x591.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102059\/crystalx-rat5-455x350.png 455w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102059\/crystalx-rat5-740x569.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102059\/crystalx-rat5-364x280.png 364w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102059\/crystalx-rat5-800x615.png 800w\" sizes=\"auto, (max-width: 1360px) 100vw, 1360px\"><\/a><\/p>\n<h3 id=\"prank-commands\">Prank commands<\/h3>\n<p>The finishing touch is a separate section of the panel named \u201cRofl\u201d with commands whose functions consist of various pranks on the victim.<\/p>\n<ul>\n<li><strong>Setting a background:<\/strong> downloading an image from a specified URL and using it as the desktop background.<\/li>\n<li><strong>Display orientation: <\/strong>rotating the screen 90\u00b0,\u202f180\u00b0, or\u202f270\u00b0.<\/li>\n<li><strong>System shutdown:<\/strong> the panel has two different buttons \u201cVoltage Drop\u201d and \u201cBSoD\u201d, but malware analysis shows that both commands perform a regular shutdown using the appropriate utility.<\/li>\n<li><strong>Remapping mouse buttons:<\/strong> swapping left click with right click and the other way round.<\/li>\n<li><strong>Peripherals disruption:<\/strong> disconnecting the monitor and blocking the input from the mouse and keyboard.<\/li>\n<li><strong>Notifications:<\/strong> displaying a window with a custom title and message.<\/li>\n<li><strong>Cursor shake:<\/strong> a special command starts a loop in which the cursor position changes chaotically at short intervals.<\/li>\n<li><strong>Disabling components:<\/strong> hiding all file icons on the desktop, disabling the taskbar, task manager, and <code>cmd.exe<\/code>.<\/li>\n<\/ul>\n<p>Moreover, the attacker can send a message to the victim, after which a dialog window will open in the system, allowing a bidirectional chat.<\/p>\n<p><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102222\/crystalx-rat6.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-119290\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102222\/crystalx-rat6.png\" alt=\"\" width=\"1016\" height=\"779\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102222\/crystalx-rat6.png 1016w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102222\/crystalx-rat6-300x230.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102222\/crystalx-rat6-768x589.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102222\/crystalx-rat6-456x350.png 456w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102222\/crystalx-rat6-740x567.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102222\/crystalx-rat6-365x280.png 365w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/31102222\/crystalx-rat6-800x613.png 800w\" sizes=\"auto, (max-width: 1016px) 100vw, 1016px\"><\/a><\/p>\n<h2 id=\"conclusions\">Conclusions<\/h2>\n<p>The sheer variety of available RATs has perpetuated demand, as actors prioritize flexibility of existing malware and its infrastructure. Thus, CrystalX RAT represents a highly functional MaaS platform that is not limited to espionage capabilities\u202f\u2013\u202fspyware, keylogging and remote control\u202f\u2013\u202fbut includes unique stealer and prankware features. At the moment, the vector of the initial infection is not precisely known, but it affects dozens of victims. Although to date, we have only seen infection attempts in Russia, the MaaS itself has no regional restrictions meaning it may attack anywhere around the globe. Moreover, our telemetry has recorded new implant versions, which indicates that this malware is still being actively developed and maintained. Combined with the growing PR campaign for CrystalX RAT, it can be concluded that the number of victims can increase significantly in the near future.<\/p>\n<h2 id=\"indicators-of-compromise\">Indicators of Compromise<\/h2>\n<p><strong># C2 infrastructure<\/strong><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/webcrystal.lol\/?icid=gl_sl_opentip-lnk_sm-team_b62870a760612f9c&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\">webcrystal[.]lol<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/webcrystal.sbs\/?icid=gl_sl_opentip-lnk_sm-team_8161532927ccfe61&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\">webcrystal[.]sbs<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/crystalxrat.top\/?icid=gl_sl_opentip-lnk_sm-team_399440acf2385fe6&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\">crystalxrat[.]top<\/a><\/p>\n<p><strong># CrystalX RAT implants<\/strong><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/47accb0ecfe8ccd466752dde1864f3b0\/?icid=gl_sl_opentip-lnk_sm-team_24fb1401088c575e&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\">47ACCB0ECFE8CCD466752DDE1864F3B0<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/2dbe6de177241c144d06355c381b868c\/?icid=gl_sl_opentip-lnk_sm-team_c9e03cb51a02ca75&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\">2DBE6DE177241C144D06355C381B868C<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/49c74b302bfa32e45b7c1c5780dd0976\/?icid=gl_sl_opentip-lnk_sm-team_e175ecee1c2d3844&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\">49C74B302BFA32E45B7C1C5780DD0976<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/88c60df2a1414cbf24430a74ae9836e0\/?icid=gl_sl_opentip-lnk_sm-team_7cc1713a1b4917bc&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\">88C60DF2A1414CBF24430A74AE9836E0<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/e540e9797e3b814bfe0a82155dfe135d\/?icid=gl_sl_opentip-lnk_sm-team_4f1eaa8db36822f4&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\">E540E9797E3B814BFE0A82155DFE135D<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/1a68ae614fb2d8875cb0573e6a721b46\/?icid=gl_sl_opentip-lnk_sm-team_a374de5853a4fd72&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\">1A68AE614FB2D8875CB0573E6A721B46<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Introduction In March\u202f2026, we discovered an active campaign promoting previously unknown malware in private Telegram chats. The Trojan was offered as a MaaS (malware\u2011as\u2011a\u2011service) with three subscription tiers. It caught our attention because of its extensive arsenal of capabilities. On the panel provided to third\u2011party actors, in addition to the standard features of RAT\u2011like malware, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-container-style":"default","site-container-layout":"default","site-sidebar-layout":"default","disable-article-header":"default","disable-site-header":"default","disable-site-footer":"default","disable-content-area-spacing":"default","footnotes":""},"categories":[924,90,922,99,232,233,682,925,923,100,236,503,257],"tags":[91],"class_list":["post-2236","post","type-post","status-publish","format-standard","hentry","category-crustalx-rat","category-cybersecurity","category-keyloggers","category-malware","category-malware-descriptions","category-malware-technologies","category-malware-as-a-service","category-prankware","category-rat-trojan","category-spyware","category-trojan","category-trojan-stealer","category-windows-malware","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>A laughing RAT: CrystalX combines spyware, stealer, and prankware features - Imperative Business Ventures Limited<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A laughing RAT: CrystalX combines spyware, stealer, and prankware features - Imperative Business Ventures Limited\" \/>\n<meta property=\"og:description\" content=\"Introduction In March\u202f2026, we discovered an active campaign promoting previously unknown malware in private Telegram chats. The Trojan was offered as a MaaS (malware\u2011as\u2011a\u2011service) with three subscription tiers. It caught our attention because of its extensive arsenal of capabilities. On the panel provided to third\u2011party actors, in addition to the standard features of RAT\u2011like malware, [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/\" \/>\n<meta property=\"og:site_name\" content=\"Imperative Business Ventures Limited\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-01T06:04:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"headline\":\"A laughing RAT: CrystalX combines spyware, stealer, and prankware features\",\"datePublished\":\"2026-04-01T06:04:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/\"},\"wordCount\":1268,\"image\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"CrustalX RAT\",\"Cybersecurity\",\"Keyloggers\",\"Malware\",\"Malware descriptions\",\"Malware Technologies\",\"Malware-as-a-Service\",\"Prankware\",\"RAT Trojan\",\"spyware\",\"Trojan\",\"Trojan-stealer\",\"Windows malware\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/\",\"url\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/\",\"name\":\"A laughing RAT: CrystalX combines spyware, stealer, and prankware features - Imperative Business Ventures Limited\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg\",\"datePublished\":\"2026-04-01T06:04:59+00:00\",\"author\":{\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#primaryimage\",\"url\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg\",\"contentUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.ibvl.in\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A laughing RAT: CrystalX combines spyware, stealer, and prankware features\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.ibvl.in\/#website\",\"url\":\"https:\/\/blog.ibvl.in\/\",\"name\":\"Imperative Business Ventures Limited\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.ibvl.in\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/blog.ibvl.in\"],\"url\":\"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A laughing RAT: CrystalX combines spyware, stealer, and prankware features - Imperative Business Ventures Limited","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/","og_locale":"en_US","og_type":"article","og_title":"A laughing RAT: CrystalX combines spyware, stealer, and prankware features - Imperative Business Ventures Limited","og_description":"Introduction In March\u202f2026, we discovered an active campaign promoting previously unknown malware in private Telegram chats. The Trojan was offered as a MaaS (malware\u2011as\u2011a\u2011service) with three subscription tiers. It caught our attention because of its extensive arsenal of capabilities. On the panel provided to third\u2011party actors, in addition to the standard features of RAT\u2011like malware, [&hellip;]","og_url":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/","og_site_name":"Imperative Business Ventures Limited","article_published_time":"2026-04-01T06:04:59+00:00","og_image":[{"url":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg","type":"","width":"","height":""}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#article","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/"},"author":{"name":"admin","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"headline":"A laughing RAT: CrystalX combines spyware, stealer, and prankware features","datePublished":"2026-04-01T06:04:59+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/"},"wordCount":1268,"image":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#primaryimage"},"thumbnailUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg","keywords":["Cybersecurity"],"articleSection":["CrustalX RAT","Cybersecurity","Keyloggers","Malware","Malware descriptions","Malware Technologies","Malware-as-a-Service","Prankware","RAT Trojan","spyware","Trojan","Trojan-stealer","Windows malware"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/","url":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/","name":"A laughing RAT: CrystalX combines spyware, stealer, and prankware features - Imperative Business Ventures Limited","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#primaryimage"},"image":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#primaryimage"},"thumbnailUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg","datePublished":"2026-04-01T06:04:59+00:00","author":{"@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"breadcrumb":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#primaryimage","url":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg","contentUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/01052848\/SL-CrystalX-RAT-and-prankware-featured-990x400.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/01\/a-laughing-rat-crystalx-combines-spyware-stealer-and-prankware-features\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.ibvl.in\/"},{"@type":"ListItem","position":2,"name":"A laughing RAT: CrystalX combines spyware, stealer, and prankware features"}]},{"@type":"WebSite","@id":"https:\/\/blog.ibvl.in\/#website","url":"https:\/\/blog.ibvl.in\/","name":"Imperative Business Ventures Limited","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.ibvl.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/blog.ibvl.in"],"url":"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/2236","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/comments?post=2236"}],"version-history":[{"count":0,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/2236\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/media?parent=2236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/categories?post=2236"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/tags?post=2236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}