A new generation of information-stealing malware, or infostealers, is rapidly evolving, with tools like RedLine, Vidar, Lumma, and the newly identified SantaStealer enabling attackers to bypass traditional security controls. These infostealers are designed not just to steal credentials, but to capture session cookies, browser fingerprints, and sensitive files, allowing adversaries to impersonate users and access corporate resources even when strong passwords and multi-factor authentication are in place. The malware is often distributed via compromised personal or unmanaged devices, and the stolen data is commoditized in underground markets, fueling a thriving log economy where digital identities are bought and sold for further exploitation.
Recent research highlights the sophistication of new infostealer variants such as SantaStealer, which operates in-memory to evade detection, exfiltrates data in compressed chunks, and is actively marketed on underground forums. The industrialization of identity theft through these tools poses significant risks to organizations, as attackers can gain persistent access to sensitive systems and data. Security teams are urged to recognize that infostealers are not merely another malware category, but a critical threat vector that requires comprehensive detection, response, and user education strategies beyond simple credential resets or malware removal.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
An Infosec Writeups article described the broader ecosystem around infostealers such as RedLine, Vidar, and Lumma, emphasizing how stolen 'full logs' containing cookies, device fingerprints, credentials, and files are monetized in real time on Telegram channels. The piece highlighted gaming lures, cracked software, BYOD exposure, and the need for identity-focused defenses and proactive monitoring for leaked credentials.
Rapid7 Labs disclosed technical details on SantaStealer, including its in-memory design, browser and application theft modules, ChromeElevator-based browser decryption bypass, and exfiltration over unencrypted HTTP to hard-coded C2 servers. The report also published indicators of compromise such as sample hashes and C2 IP addresses, noting the actor's weak operational security.
Rapid7 reported that a new malware-as-a-service infostealer, SantaStealer, previously known as BluelineStealer, was being promoted on Telegram and underground forums with a planned release before the end of 2025. The service was advertised with affiliate pricing between $175 and $300 per month and targeting options including avoidance of CIS countries.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.