logo

SantaStealer stuffs credentials, crypto wallets into a brand new bag

ID: cf87aeac-d0ec-50bd-bece-b545f0e7cd34

STIX ID: report--cf87aeac-d0ec-50bd-bece-b545f0e7cd34

Feed Name: The Register (Security)

Threat Score
68/100

Date Published: 2025-12-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

SantaStealer is a newly advertised Russian-speaking infostealer (a rebrand of Blueline Stealer) that targets credentials, sensitive documents, and crypto wallets; Rapid7 analysis shows unobfuscated 64-bit DLL samples with basic anti-VM/debug checks, in-memory module loading, HTTP-based exfiltration, and numerous cleartext strings and exported symbols that make analysis straightforward. The developers market basic and premium tiers via Telegram and a Russian forum with affiliate panels (pricing $175/$300 per month), and the report includes IoCs and recommendations to avoid suspicious links, attachments, and social-engineering prompts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.