SantaStealer Attacks Users to Exfiltrates Sensitive Documents, Credentials, and Wallet Data
The emergence of SantaStealer, a new information-stealing malware, poses a significant threat to Windows users. This malware-as-a-service is being promoted on Telegram and underground forums, with a full release anticipated by the end of 2025.…
The emergence of SantaStealer, a new information-stealing malware, poses a significant threat to Windows users. This malware-as-a-service is being promoted on Telegram and underground forums, with a full release anticipated by the end of 2025. SantaStealer is a rebranding of the previous BluelineStealer, illustrating the continuous advancement of cybercrime tools designed to extract sensitive user data.
Capabilities and Technical Specifications
SantaStealer is equipped to collect and exfiltrate sensitive documents, user credentials, cryptocurrency wallet data, and information from various applications. It operates entirely in memory, evading detection by traditional security solutions. The stolen data is compressed, segmented into 10 MB chunks, and transmitted to a command-and-control server via unencrypted HTTP connections.
The malware is reportedly written in C, featuring a polymorphic engine and anti-detection capabilities. However, researchers have identified samples lacking obfuscation, revealing operational security weaknesses.
In-Memory Infection and Browser Credential Theft
The malware was identified through a Windows executable that triggered detection rules similar to the Raccoon stealer family. Analysis of a 64-bit DLL with descriptive symbols exposed its credential-stealing capabilities. SantaStealer uses a modular design, detecting virtual machines before executing its payload.
The emergence of SantaStealer, a new information-stealing malware, poses a significant threat to Windows users.
It targets browser credentials from Chromium-based browsers by bypassing App-Bound Encryption. This is achieved through ChromElevator, a tool that performs reflective process hollowing to inject code into legitimate browser processes. The stolen data is exfiltrated over HTTP to specified command-and-control servers on port 6767.
The malware-as-a-service is priced between $175 per month for basic features and $300 for premium options, which include custom implementation and file binding capabilities.
Security professionals are advised to be cautious of unrecognized email attachments and suspicious download links that may distribute this malware.
Based on reporting by Cyber Security News.
