Kaspersky logo. /Courtesy of Kaspersky

Kaspersky said on the 20th that its Global Research and Analysis Team (GReAT) has discovered a previously undisclosed remote access Trojan (RAT) called "CrystalX RAT."

The malware combines typical remote-control capabilities with a stealer, a keylogger (keystroke recording), a clipper (malware that automatically swaps a cryptocurrency wallet address with one predesignated by the attacker), and spyware into a single piece of malware.

Kaspersky warned that attackers are selling it as malware-as-a-service (MaaS), promoting it aggressively on YouTube and Telegram, which is increasing the likelihood that attackers with low skill levels will use it.

"CrystalX RAT" steals system information and major account credentials for services such as Steam, Discord, and Telegram, and also collects data saved in web browsers. Beyond data theft, it is equipped with functions that can comprehensively monitor victims. With features such as screen capture, microphone audio recording, webcam filming, and real-time screen recording, it can effectively monitor all of a victim's activities.

With prankware functions that confuse victims, it can forcibly shake the victim's mouse cursor, change the desktop background, rotate the screen orientation, hide desktop icons, or forcibly shut down the system. Kaspersky said, "These features may seem like simple pranks, but they continuously disrupt the victim's system and create psychological anxiety, compounding the damage of the attack."

Leonid Bezvershenko, senior security researcher at Kaspersky's Global Research and Analysis Team, said, "'CrystalX RAT' can virtually take full control of a victim's system and completely compromise personal information," and "While the initial infection vector has not been precisely identified, dozens of victims have already been confirmed."

Lee Hyo-eun, head of Kaspersky Korea, said, "Domestic attackers can easily obtain these remote-control malware tools, which are inexpensive yet packed with features, through social media, further lowering the barrier to entry for cybercrime," and "Both corporations and general users must break the habit of casually downloading files and build security frameworks that protect endpoints across the board to prepare for composite attacks that combine surveillance, credential theft, and system manipulation."

※ This article has been translated by AI. Share your feedback here.