A laughing RAT: CrystalX combines spyware, stealer, and prankware features

2026-04-01T08:51:53Zbfb21e37706765f2f6a9f91fb2385a08359d8e274f34cfd302951ee13801f8d5
Android TrojanArkanix StealerBeatBankerCorunaCrystalXGoPixHorabotLiteLLMMaaSOperation TriangulationPACProxy AutoConfigRATbanking trojancrypto mineriOS kernel exploitinfostealermalvertisingman-in-the-middlememory-only implantmobile malware reportprankwarespywarestealersupply-chain

What happened

Kaspersky Securelist batch covering multiple high-risk trends and campaigns: a new CrystalX RAT offered as MaaS that combines spyware, stealer and so-called prankware; a supply‑chain compromise of the LiteLLM AI gateway enabling data theft; the Coruna exploit kit (updated Operation Triangulation) leveraging iOS kernel exploits; and several active malware families and campaigns — Horabot (targeting Mexico), GoPix (memory‑only Brazilian banking Trojan using PAC files and malvertising), BeatBanker (dual‑mode Android crypto‑miner and banker), and Arkanix stealer (C++/Python MaaS). Also included: Q

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
bfb21e37706765f2f6a9f91fb2385a08359d8e274f34cfd302951ee13801f8d5
Enrichment time
2026-04-01T08:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · A laughing RAT: CrystalX combines spyware, stealer, and prankware features · Baitaphish