PULSE NAME
A laughing RAT: CrystalX combines spyware; stealer; and prankware features
WHITE AlienVault 2026-04-01 Modified: 2026-04-01
9
IOCs
LOW VOLUME
In March 2026, a new MaaS active campaign was discovered promoting previously unknown malware in private Telegram chats. The Trojan features an extensive arsenal of capabilities. On the panel provided to third‑party actors, in addition to the standard features of RAT‑like malware, a stealer, keylogger, clipper, and spyware are also available.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
CrystalX
Indicators of Compromise (9)
All FileHash-MD5 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1a68ae614fb2d8875cb0573e6a721b46 2026-04-01
FileHash-MD5 2dbe6de177241c144d06355c381b868c 2026-04-01
FileHash-MD5 47accb0ecfe8ccd466752dde1864f3b0 2026-04-01
FileHash-MD5 49c74b302bfa32e45b7c1c5780dd0976 2026-04-01
FileHash-MD5 88c60df2a1414cbf24430a74ae9836e0 2026-04-01
FileHash-MD5 e540e9797e3b814bfe0a82155dfe135d 2026-04-01
domain crystalxrat.top 2026-04-01
domain webcrystal.lol 2026-04-01
domain webcrystal.sbs 2026-04-01