A laughing RAT: CrystalX combines spyware, stealer, and prankware features
ATT&CK techniques detected
T1204.004Malicious Copy and Paste
46%
“single js script namedcontent. js. - the content. js script is dynamically generated, containing regular expressions for crypto wallet addresses ( such as bitcoin, litecoin, monero, avalanche, doge, and others ) and substitution values. - the generated script is activated via the…”
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
T1204.002Malicious File
39%
“a laughing rat : crystalx combines spyware, stealer, and prankware features introduction in march 2026, we discovered an active campaign promoting previously unknown malware in private telegram chats. the trojan was offered as a maas ( malware ‑ as ‑ a ‑ service ) with three subs…”
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
Summary
Kaspersky researchers analyze a new CrystalX RAT distributed as MaaS and featuring extensive spyware, stealer, and prankware capabilities.