Last seven days
- First activity
- Jul 19, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
SantaStealer is a Windows malware-as-a-service information stealer, also described as a rebrand of BlueLineStealer/BluelineStealer, that began public promotion on Telegram and underground forums in late 2025 with a planned release before the end of 2025 and reporting of first release in December 2025.
Profile source: Mallory opens in a new tabSantaStealer
SantaStealer is a Windows malware-as-a-service information stealer, also described as a rebrand of BlueLineStealer/BluelineStealer, that began public promotion on Telegram and underground forums in late 2025 with a planned release before the end of 2025 and reporting of first release in December 2025. It is marketed by Russian-speaking operators and multiple sources assess it as likely tied to the Russian-speaking cybercrime ecosystem; its panel and configuration also support excluding CIS/Russian-speaking systems. SantaStealer is modular and multi-threaded, with 14 data-collection modules reported in current analyses. It targets browser credentials and data including passwords, cookies, history, credit cards, browser sessions, and autofill data; cryptocurrency wallets; messaging and application data including Telegram, Discord, and Steam; screenshots; sensitive documents; and broader application data. Current reporting states it is written in C and uses statically linked libraries including cJSON, miniz, and sqlite3. Samples have been described as 64-bit Windows DLLs with hundreds of exported functions and descriptive symbols. The malware is advertised as operating primarily or entirely in memory to evade file-based detection, and reporting notes that modules and a Chrome decryptor DLL are loaded in-memory as part of a shift toward fileless collection. For Chromium credential theft, analyses report use of an embedded executable or ChromElevator-based component to bypass App-Bound Encryption, including DLL injection/direct syscalls and reflective process hollowing techniques. SantaStealer performs configuration checks, delayed execution, optional CIS-region termination via keyboard layout detection, and basic anti-analysis measures such as process blacklists, uptime checks, service queries, anti-VM checks, and anti-debugging. Stolen data is collected in memory, archived into ZIP files such as Log.zip, split into 10 MB chunks, and exfiltrated to hard-coded command-and-control endpoints over unencrypted HTTP; some reporting specifies port 6767 and HTTP POST requests with unique identifiers and campaign tags. Publicly reported C2 indicators include 31[.]57[.]38[.]244:6767 and 80[.]76[.]49[.]114:6767. Despite advertising claims of being fully undetected and highly evasive, multiple analyses state current samples are rudimentary, unobfuscated, and easy to analyze, with unencrypted strings, plain-text configuration, and leaked samples exposing descriptive function names and symbols. SantaStealer has also been observed as a payload family distributed by Amadey botnet/pay-per-install campaigns in March 2026 alongside other stealers and RATs. Distribution methods are not definitively established in the provided content, but reporting notes likely or possible vectors including phishing, pirated software, torrent downloads, malvertising, ClickFix/social engineering, deceptive YouTube comments, and broader underground affiliate distribution.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 8cf9bd9dd07635e07a8e534b38355effa6d5c9f96d9983830b9b840aa1138f78 MITRE ATT&CK
Reporting
We also added a new configuration extractor for SantaStealer, a Malware-as-a-Service infostealer that was first released in December 2025. SantaStealer is commonly described as a rebrand of the earlier BlueLine stealer, continuing the same goal of harvesting sensitive information from infected systems.
The Amadey botnet drops information stealers (Vidar, LummaStealer, SalatStealer, RustyStealer, SantaStealer) to harvest credentials, browser sessions, and crypto wallets.
A single Amadey instance is distributing 100 unique samples spanning 24 malware families . The customer list reads like a who's-who of commodity threats: ... SantaStealer 5 Info Stealer
...PAYLOADS ... SantaStealer (5) SalatStealer (4) CoinMiner (3)...
SantaStealer 3 Emerging stealer family, limited public reporting
SantaStealer is a new information stealer actively marketed on Telegram channels and underground forums, with a planned release before the end of 2025. Analysis of leaked samples reveals a discrepancy between the operators' bold claims of advanced evasion and the malware's current rudimentary implementation.
SantaStealer is Coming to Town: A New, Ambitious Infostealer Advertised on Underground Forums
A new, modular information stealer named SantaStealer is being advertised by Russian-speaking operators on Telegram and underground forums like Lolz. "The malware collects and exfiltrates sensitive documents, credentials, wallets, and data from a broad range of applications, and aims to operate entirely in-memory to avoid file-based detection," Rapid7 said.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.