Skip to content
Malware family

SantaStealer

SantaStealer is a Windows malware-as-a-service information stealer, also described as a rebrand of BlueLineStealer/BluelineStealer, that began public promotion on Telegram and underground forums in late 2025 with a planned release before the end of 2025 and reporting of first release in December 2025.

Profile source: Mallory opens in a new tab

SantaStealer

Family profile

SantaStealer is a Windows malware-as-a-service information stealer, also described as a rebrand of BlueLineStealer/BluelineStealer, that began public promotion on Telegram and underground forums in late 2025 with a planned release before the end of 2025 and reporting of first release in December 2025. It is marketed by Russian-speaking operators and multiple sources assess it as likely tied to the Russian-speaking cybercrime ecosystem; its panel and configuration also support excluding CIS/Russian-speaking systems. SantaStealer is modular and multi-threaded, with 14 data-collection modules reported in current analyses. It targets browser credentials and data including passwords, cookies, history, credit cards, browser sessions, and autofill data; cryptocurrency wallets; messaging and application data including Telegram, Discord, and Steam; screenshots; sensitive documents; and broader application data. Current reporting states it is written in C and uses statically linked libraries including cJSON, miniz, and sqlite3. Samples have been described as 64-bit Windows DLLs with hundreds of exported functions and descriptive symbols. The malware is advertised as operating primarily or entirely in memory to evade file-based detection, and reporting notes that modules and a Chrome decryptor DLL are loaded in-memory as part of a shift toward fileless collection. For Chromium credential theft, analyses report use of an embedded executable or ChromElevator-based component to bypass App-Bound Encryption, including DLL injection/direct syscalls and reflective process hollowing techniques. SantaStealer performs configuration checks, delayed execution, optional CIS-region termination via keyboard layout detection, and basic anti-analysis measures such as process blacklists, uptime checks, service queries, anti-VM checks, and anti-debugging. Stolen data is collected in memory, archived into ZIP files such as Log.zip, split into 10 MB chunks, and exfiltrated to hard-coded command-and-control endpoints over unencrypted HTTP; some reporting specifies port 6767 and HTTP POST requests with unique identifiers and campaign tags. Publicly reported C2 indicators include 31[.]57[.]38[.]244:6767 and 80[.]76[.]49[.]114:6767. Despite advertising claims of being fully undetected and highly evasive, multiple analyses state current samples are rudimentary, unobfuscated, and easy to analyze, with unencrypted strings, plain-text configuration, and leaked samples exposing descriptive function names and symbols. SantaStealer has also been observed as a payload family distributed by Amadey botnet/pay-per-install campaigns in March 2026 alongside other stealers and RATs. Distribution methods are not definitively established in the provided content, but reporting notes likely or possible vectors including phishing, pirated software, torrent downloads, malvertising, ClickFix/social engineering, deceptive YouTube comments, and broader underground affiliate distribution.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 19, 2026
Last activity
Jul 20, 2026
Feed role
C2
Host form
2 IP / 0 hostnames

Leading locations

  • LU1
  • US1

Leading providers

  • 12651980 CANADA INC.1
  • Ghosty Networks LLC1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

MITRE ATT&CK

SantaStealer in ATT&CK

3 distinct techniques

Reporting

Research mentioning SantaStealer

Mar 13
Vmray

VMRay Detection Highlights: New threat identifiers, Config Extractors & YARA Rules

We also added a new configuration extractor for SantaStealer, a Malware-as-a-Service infostealer that was first released in December 2025. SantaStealer is commonly described as a rebrand of the earlier BlueLine stealer, continuing the same goal of harvesting sensitive information from infected systems.

Mar 12
Breakglass Intel

Amadey Botnet Campaign "fbf543" Weaponizes 9 Legitimate RMM Tools Across 5 Vendors for EDR-Evasive Persistence - Breakglass Intelligence - Breakglass Intelligence

The Amadey botnet drops information stealers (Vidar, LummaStealer, SalatStealer, RustyStealer, SantaStealer) to harvest credentials, browser sessions, and crypto wallets.

Mar 12
Breakglass Intel

Amadey's Marketplace: Inside a 100-Sample Pay-Per-Install Operation Distributing Vidar, XWorm, and 22 Other Malware Families - Breakglass Intelligence - Breakglass Intelligence

A single Amadey instance is distributing 100 unique samples spanning 24 malware families . The customer list reads like a who's-who of commodity threats: ... SantaStealer 5 Info Stealer

Mar 12
Breakglass Intel

Amadey v5.x "fbf543" Campaign: A Pay-Per-Install Supermarket Running 24 Malware Families on Bulletproof Rails - Breakglass Intelligence - Breakglass Intelligence

...PAYLOADS ... SantaStealer (5) SalatStealer (4) CoinMiner (3)...

Mar 12
Breakglass Intel

LummaStealer's Go Loader and the fbf543 Amadey Supermarket: 50 Payloads, 13 Malware Families, and the Bulletproof Host That Ties It All Together - Breakglass Intelligence - Breakglass Intelligence

SantaStealer 3 Emerging stealer family, limited public reporting

Dec 23
Polyswarm

SantaStealer

SantaStealer is a new information stealer actively marketed on Telegram channels and underground forums, with a planned release before the end of 2025. Analysis of leaked samples reveals a discrepancy between the operators' bold claims of advanced evasion and the malware's current rudimentary implementation.

Dec 21
Securityaffairs

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 76

SantaStealer is Coming to Town: A New, Ambitious Infostealer Advertised on Underground Forums

Dec 18
The Hacker News

ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

A new, modular information stealer named SantaStealer is being advertised by Russian-speaking operators on Telegram and underground forums like Lolz. "The malware collects and exfiltrates sensitive documents, credentials, wallets, and data from a broad range of applications, and aims to operate entirely in-memory to avoid file-based detection," Rapid7 said.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.