TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Kaspersky Securelist

A laughing RAT: CrystalX combines spyware, stealer, and prankware features

GReAT · 2026-04-01 · Read original ↗

ATT&CK techniques detected

2 predictions
T1204.004Malicious Copy and Paste
46%
"single js script namedcontent. js. - the content. js script is dynamically generated, containing regular expressions for crypto wallet addresses ( such as bitcoin, litecoin, monero, avalanche, doge, and others ) and substitution values. - the generated script is activated via the…"
T1204.002Malicious File
39%
"a laughing rat : crystalx combines spyware, stealer, and prankware features introduction in march 2026, we discovered an active campaign promoting previously unknown malware in private telegram chats. the trojan was offered as a maas ( malware ‑ as ‑ a ‑ service ) with three subs…"

Summary

Kaspersky researchers analyze a new CrystalX RAT distributed as MaaS and featuring extensive spyware, stealer, and prankware capabilities.