A new information stealer known as SantaStealer has surfaced, posing a significant threat to Windows users by exfiltrating sensitive documents, credentials, and cryptocurrency wallet data. Marketed aggressively on Telegram and underground forums, SantaStealer is a rebranded version of BluelineStealer and is being offered as a malware-as-a-service (MaaS) platform with customizable modules. The malware operates entirely in memory to evade traditional detection, compresses stolen data into 10 MB chunks, and transmits it to command-and-control servers via unencrypted HTTP. Rapid7 researchers have analyzed samples of SantaStealer, revealing that despite claims of advanced anti-detection features, the malware contains operational security weaknesses, such as unstripped symbols and unencrypted strings, making it easier to analyze.
SantaStealer's web panel allows threat actors to tailor the malware's configuration, including the ability to activate or deactivate up to 14 modules, integrate Telegram bot tokens for data exfiltration, and deploy fake error pages to distract victims. The MaaS is offered in basic and premium plans, with the latter including additional features like a crypto clipper and a polymorphic C engine. While the developers claim the malware is fully undetectable, security researchers have found it to be "ambitious but amateurish," with its final capabilities still under development. The emergence of SantaStealer highlights the ongoing evolution of the cybercrime ecosystem and the increasing sophistication of tools available to threat actors targeting sensitive user information.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Following the technical analysis, researchers published indicators of compromise and advised defenders to watch for suspicious links, attachments, downloads, and social-engineering lures that could deliver the infostealer. Reporting noted that the malware's simplicity reduced its sophistication but still left it dangerous for credential and wallet theft.
Rapid7 disclosed that SantaStealer includes 14 modules targeting browsers, messaging apps, cryptocurrency wallets, documents, and other applications, with in-memory loading, a web affiliate panel, and data exfiltration over unencrypted HTTP. The researchers also found its claims of being fully undetected were overstated because samples contained unobfuscated code, unencrypted strings, and weak operational security.
Rapid7 researchers examined SantaStealer samples, attributed the operation to Russian-speaking actors associated with the handles "Cracked" and "Furix," and found the malware avoids infecting systems with Russian keyboard settings. Their analysis concluded the malware was still under active development rather than a mature, widely deployed threat.
SantaStealer emerged on Telegram and Russian-speaking cybercrime forums as a malware-as-a-service offering and was identified as a rebrand of the earlier BluelineStealer. The service was marketed with subscription pricing and a planned release before the end of 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourceesecurityplanet.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.