New CrystalRAT malware adds RAT, stealer and prankware features

2026-04-02T01:23:30Z643e648b63400f0659b23b063e1dc11841046bbc96854504e8eb59569b56c67a
AndroidBECChrome zero-dayCrystalRATDarkSwordEvilTokensGIGABYTE Control CenterGoogle PlayMicrosoft account takeoverNoVoiceRATTelegramTrueConfarbitrary file write vulnerability (AWR) potential exploitclipboard hijackdevice code phishingiOS 18keyloggermalwaremalware-as-a-servicemobile malwaresoftware update compromisestealersupply-chain attackzero-day

What happened

Multiple active threats and security developments: a new Malware-as-a-Service called CrystalRAT is being promoted on Telegram offering RAT, stealer, keylogging and clipboard-hijack/prankware features; the EvilTokens kit enables device-code phishing to hijack Microsoft accounts and fuel BEC; NoVoice Android malware found in >50 Google Play apps infected an estimated 2.3M devices; attackers exploited a TrueConf zero-day to push malicious software updates to connected endpoints; Apple expanded iOS 18 update coverage to block DarkSword exploit-kit attacks; Google patched the fourth Chrome zero-day

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
643e648b63400f0659b23b063e1dc11841046bbc96854504e8eb59569b56c67a
Enrichment time
2026-04-02T01:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New CrystalRAT malware adds RAT, stealer and prankware features · Baitaphish