HomeSecuritySantaStealer malware steals documents and credentials

SantaStealer malware steals documents and credentials

A new and particularly worrying malware is making its appearance in the cybercrime ecosystem, targeting millions of Windows worldwide. The tool is called SantaStealer and is already being characterized by researchers as one of the most dangerous emerging threats in the information theft.

SantaStealer malware

Malware-as-a-Service and underground distribution

SantaStealer is available as malware-as-a-service (MaaS) and is being aggressively promoted through Telegram channels and closed hacker forums on the dark web. Its creators promise a full commercial release before the end of 2025, targeting both organized crime groups and “individual” cybercriminals looking for ready-made attack tools.

In essence, SantaStealer is a redesign of the well-known BluelineStealer, confirming a consistent trend: info-stealers are not disappearing, but evolving, becoming more modular, harder to detect, and clearly more efficient.

See also: React2Shell vulnerability used to install Linux Backdoors

SantaStealer: What data does it steal and how does it work?

The capabilities of SantaStealer are impressive. The malware targets documents, user credentials, crypto wallet data, as well as information from a number of popular applications. All of this is collected silently and without any visible traces on the system.

One of its most worrying features is its memory-only execution, which avoids traditional file-based detection mechanisms, making classic antiviruses much less effective.

SantaStealer malware steals documents and credentials

Once the data is collected, it is compressed, split into 10 MB packets, and sent to command-and-control servers via simple HTTP connections, without encryption — a point that raises questions about the level of operational security of the perpetrators.

Creators' claims vs reality

SantaStealer developers advertise that the malware is written entirely in C, incorporates a custom polymorphic engine , and features advanced anti-detection techniques. However, the real picture seems to be more complex.

See also: NexusRoute: New malware campaign targets Android users

Rapid7 researchers analyzed unobfuscated samples of SantaStealer , revealing implementation weaknesses and significant functional security gaps. The analysis shows that, despite the serious threat it poses, the malware is not as “invulnerable” as its creators claim.

Stealing credentials from browsers using advanced techniques

The analysis began when a suspicious Windows executable that triggered generic detection rules similar to those of the Raccoon Stealer family. A 64-bit DLL with over 500 exported symbols and revealing names, such as payload_main and check_antivm, quickly betrayed the tool's true capabilities.

SantaStealer follows a modular architecture and checks if it is running in a virtual environmentbefore activating the main payload. The method of stealing credentials from Chromium-based browsers is particularly sophisticated.

See also: Phantom Stealer: Phishing attack with ISO images targets Russia

It uses a built-in tool called ChromElevator, which uses syscall-based reflective process hollowing to inject code into legitimate browser processes. This bypasses AppBound Encryption and decrypts stored credentials, without immediately raising suspicion.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

SantaStealer malware steals documents and credentials

Cost and targeting of the MaaS ecosystem

SantaStealer's pricing ranges from $175 per month for basic use to $300 for premium packages, which include customizations, file binders, and technical support. This model dramatically lowers the barrier to entry for cybercriminals.

What users and organizations should be aware of

For security professionals, SantaStealer is yet another reminder that info-stealers remain a mainstay of modern cybercrime. Users are urged to be extra cautious with suspicious emails, attachments, and download links, while organizations should invest in behavioral detection and memory protection.

SantaStealer clearly shows where the future of malicious tools is headed: quieter, more commercial, and more dangerous than ever.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS