← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
A laughing RAT: CrystalX combines spyware; stealer; and prankware features
In March 2026, a new MaaS active campaign was discovered promoting previously unknown malware in private Telegram chats. The Trojan features an extensive arsenal of capabilities. On the panel provided to third‑party actors, in addition to the standard features of RAT‑like malware, a stealer, keylogger, clipper, and spyware are also available.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
CrystalX
Indicators of Compromise (9)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 1a68ae614fb2d8875cb0573e6a721b46 | — | 2026-04-01 | |
| FileHash-MD5 | 2dbe6de177241c144d06355c381b868c | — | 2026-04-01 | |
| FileHash-MD5 | 47accb0ecfe8ccd466752dde1864f3b0 | — | 2026-04-01 | |
| FileHash-MD5 | 49c74b302bfa32e45b7c1c5780dd0976 | — | 2026-04-01 | |
| FileHash-MD5 | 88c60df2a1414cbf24430a74ae9836e0 | — | 2026-04-01 | |
| FileHash-MD5 | e540e9797e3b814bfe0a82155dfe135d | — | 2026-04-01 | |
| domain | crystalxrat.top | — | 2026-04-01 | |
| domain | webcrystal.lol | — | 2026-04-01 | |
| domain | webcrystal.sbs | — | 2026-04-01 |