Tektronix TIF 2026
This page was machine-translated and may differ from the original. View original

Kaspersky GReAT Detects Complex Function RAT Malware 'CrystalX RAT'

Google 우선 소스Published2026.07.20 09:03
Combining data theft, keyloggers, clippers, and spyware, distributed via YouTube and Telegram in the form of MaaS.

Cybersecurity firm Kaspersky's Global Research and Analysis Team (GReAT) has discovered a new type of remote access malware (Remote Access Trojan, RAT) that combines multiple malicious functions, ranging from information theft to real-time monitoring, into a single code.

Kaspersky announced on the 20th that GReAT detected a new type of RAT called 'CrystalX RAT'.

This malware has a structure that integrates the functions of an information-stealing stealer, a keylogger, a clipper, and spyware into one.

It has been confirmed that attackers are selling it to third parties in the form of MaaS and utilizing YouTube and Telegram as distribution channels.

CrystalX RAT collects extensive information from infected systems.

It can steal Steam, Discord, and Telegram account credentials and browser saved data, and use the Clipper function to replace the victim's cryptocurrency wallet address with an address specified by the attacker.

In terms of surveillance, screen capture, microphone voice recording, webcam shooting, and real-time screen recording are possible.

In addition, it is equipped with prankware features designed to disrupt victims, such as forcibly manipulating the mouse cursor, changing the desktop background, rotating the screen orientation, and forcibly shutting down the system.

"There is a possibility that the collected information could be misused for blackmail or financial extortion, going beyond the theft of account credentials," said Leonid Bezvershenko, a senior security researcher at GReAT.They stated, “The continuous detection of new versions in Kaspersky Telemetry demonstrates that it is still being actively developed and maintained.”

The initial route of infection has not yet been identified, but dozens of victims have already been confirmed.

Lee Hyo-eun, Country Manager of Kaspersky Korea, emphasized, “As such malware that can be purchased cheaply through social media spreads, the barrier to entry for cybercrime is lowering,” adding, “We must break away from the habit of mindlessly downloading files and build a security system to protect the entire endpoint.”

To prevent damage, Kaspersky recommended refraining from executing files received via messenger or email, avoiding the use of paths beyond official game or mod sites, installing a trusted security solution, and enabling the Windows file extension display feature.

Detailed analysis of CrystalX RATs and Indicators of Compromise (IoCs) can be found on Securelist.com.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
명세환 기자
명세환 기자