Skip to content

SantaStealer

According to Rapid7, this malware collects and exfiltrates sensitive documents, credentials, wallets, and data from a broad range of applications, and aims to operate entirely in-memory to avoid file-based detection. Stolen data is then compressed, split into 10 MB chunks, and sent to a C2 server over unencrypted HTTP.

C2 Infrastructure

Hosting/VPS100%

Last 7 days

Apr 13, 2026
C2 Hosts: 1
Apr 12, 2026
C2 Hosts: 1
Apr 9, 2026
C2 Hosts: 1

Further Reading