SantaStealer is a Windows information stealer sold as a malware-as-a-service offering and widely described as a rebrand of BlueLineStealer. It emerged in late 2025 and has been marketed on Telegram and Russian-language underground forums with tiered affiliate access and a builder panel for customizing payloads. Available reporting indicates likely Russian-speaking operators, supported by the affiliate ecosystem, Russian-language infrastructure choices, and optional exclusion of CIS-region victims.
The malware is modular and multi-threaded, with roughly fourteen collection components focused on harvesting credentials and other sensitive data from infected systems. Reported targets include Chromium-based browser passwords, cookies, browsing data, credit card information, messaging application data, cryptocurrency wallet data, screenshots, and selected documents. SantaStealer is also associated with techniques intended to bypass Chromium App-Bound Encryption protections through an embedded browser-decryption component. Stolen data is collected largely in memory, compressed into archives, split into chunks, and exfiltrated over HTTP to operator-controlled infrastructure.
SantaStealer has been advertised as in-memory or fileless malware designed to evade file-based detection, but public analyses of leaked samples indicate that its real-world implementation has been comparatively immature. Observed samples reportedly retained descriptive symbols and plaintext strings, and anti-analysis features were limited to basic checks such as process blacklists, uptime checks, service queries, and simple anti-VM logic. Some samples were described as 64-bit Windows DLLs with extensive exported functions and code written in C using statically linked libraries.
The malware has been observed both as a standalone MaaS stealer and as a payload delivered by other crimeware distribution services, including Amadey-based pay-per-install activity. In those campaigns, SantaStealer appeared alongside other commodity stealers, RATs, loaders, and abused remote-management tools, consistent with financially motivated cybercrime operations. Claimed delivery vectors in public reporting include phishing and other social-engineering-driven distribution, but direct high-confidence evidence in the supplied material primarily supports underground marketing and secondary delivery through malware loaders rather than a single dominant initial infection vector.
SantaStealer is best characterized as an emerging commodity infostealer whose operational model, victimology, and feature set align with the broader Russian-speaking cybercrime ecosystem. Its current technical sophistication appears lower than some established competitors, but its credential, session, document, and wallet theft capabilities still make it a meaningful threat to Windows users and organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Ces modules ciblent les identifiants enregistrés dans les navigateurs, les cookies de session...
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Malware-as-a-Service infostealer used to harvest sensitive information from infected systems.
An emerging stealer family with limited public reporting that appeared among the campaign payloads.
SantaStealer is listed as one of the malware families distributed by the Amadey pay-per-install campaign.
SantaStealer is used to steal passwords, cookies, and autofill data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.