SantaStealer is a modular malware-as-a-service information stealer operated by Russian-speaking cybercriminals and assessed as a rebrand of Blueline Stealer. It is marketed on Telegram and Russian-language underground forums and has been linked to operators using the aliases Cracked and Furix. The operation appears financially motivated and includes configuration intended to avoid infecting Russian-speaking victims, a pattern commonly associated with Russian-speaking cybercrime ecosystems. SantaStealer is designed to steal credentials, cryptocurrency wallet data, and sensitive documents from a broad range of applications. Reported samples use multiple collection modules and execute key components in memory, including a browser decryption component, to reduce reliance on dropped files and improve evasion against file-based detection. Observed builds also compress stolen data and exfiltrate it in chunks. Despite marketing claims of strong stealth, analyzed samples have been described as relatively unsophisticated, with limited anti-analysis and anti-virtualization measures, unobfuscated code, and unencrypted strings. The actor’s known capabilities center on credential theft, cryptocurrency theft, data exfiltration, and initial access enablement for downstream criminal activity. As with other infostealer operations, stolen data could support follow-on intrusion activity by other financially motivated actors, including ransomware affiliates, although SantaStealer itself is primarily an infostealer rather than a ransomware operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-speaking cybercriminals selling and operating SantaStealer, a modular infostealer malware, for credential and data theft.
The operators are responsible for developing and distributing the SantaStealer infostealer malware, which is a rebrand of the earlier Blueline Stealer. They advertise the malware on Telegram and Russian-speaking hacker forums, targeting credentials, sensitive documents, and crypto wallets. The malware is sold as a service with monthly pricing tiers and is designed to avoid detection, though current samples lack advanced evasion features.
The SantaStealer operators are responsible for developing and distributing the SantaStealer infostealer malware, a modular credential and wallet stealer. They advertise the malware on Telegram and Russian-speaking hacker forums, offering it as a service for a monthly fee. The group is financially motivated and targets sensitive documents, credentials, and crypto wallets, with a focus on avoiding Russian-speaking victims. SantaStealer is a rebrand of the earlier Blueline Stealer, operated by two individuals known as 'Cracked' and 'Furix'.
SantaStealer is a modular infostealer malware-as-a-service (MaaS) platform, advertised on cybercrime forums and Telegram, designed to steal sensitive information such as documents, credentials, cryptocurrency wallet data, and app details (e.g., Discord, Steam). It is being actively developed and marketed with customizable modules and features, including a crypto clipper and a WinRAR exploit builder.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.