SantaStealer is a new infostealer malware that targets crypto wallets and is being sold on Telegram and hacker forums.SantaStealer is a new infostealer malware that targets crypto wallets and is being sold on Telegram and hacker forums.

SantaStealer malware targets crypto wallets and browsers

2025/12/21 17:18
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

SantaStealer is a new information-stealing malware that targets crypto wallets. The malware-as-a-service (MaaS) extracts private data linked to any type of crypto.

Researchers at Rapid7 say that SantaStealer is a rebrand of another infostealer called BluelineStealer. The developer of SantaStealer is rumored to be preparing a wider launch before the year ends.

At the moment, the malware is advertised on Telegram and hacker forums, and offered as a subscription service. Basic access costs $175 per month, while Premium access is more expensive and costs $300.

The SantaStealer malware developers claim enterprise-level capability with antivirus bypasses and corporate network access.

SantaStealer targets crypto wallets

Crypto wallets are the main focus of SantaStealer. The malware targets crypto wallet apps like Exodus and browser extensions like MetaMask. It is designed to extract private data linked to digital assets.

The malware doesn’t stop there. It also steals browser data, including passwords, cookies, browsing history, and saved credit card information. Messaging platforms such as Telegram and Discord are targeted as well. Steam data and local documents are included. The malware can also capture desktop screenshots.

To do this, it drops or loads an embedded executable. That executable decrypts and injects code into the browser. This allows access to protected keys.

SantaStealer zeroes in on crypto wallets as main target.SantaStealer advertisement in Russian and English. Source: Rapid7.

SantaStealer runs many data collection modules simultaneously. Each module operates in its own thread. Stolen data is written to memory, compressed into ZIP files, and exfiltrated in 10MB chunks. The data is sent to a hardcoded command-and-control server over port 6767.

To reach wallet data stored in browsers, the malware bypasses Chrome’s App-Bound Encryption, which was introduced in July of 2024. According to Rapid7, multiple info-stealers have already defeated it.

The malware is marketed as advanced, with total evasion. But Rapid7 security researchers say the malware does not match those claims. Current samples are easy to analyze, and they expose symbols and readable strings. This suggests rushed development and weak operational security.

“The anti-analysis and stealth capabilities of the stealer advertised in the web panel remain very basic and amateurish, with only the third-party Chrome decryptor payload being somewhat hidden,” wrote Milan Spinka from Rapid7.

The affiliate panel of SantaStealer is polished. Operators can customize builds, and they can steal everything or focus only on wallet and browser data. The options also allow operators to exclude the Commonwealth of Independent States (CIS) region and delay execution.

SantaStealer has not yet spread on a large scale, and its delivery method remains unclear. Recent campaigns favor ClickFix attacks since victims are tricked into pasting malicious commands into Windows terminals.

According to the researchers, other malware delivery paths remain common. These include phishing emails, pirated software, torrents, malvertising, and deceptive YouTube comments.

Security researchers advise crypto users to stay alert and avoid unknown links and attachments.

Spinka wrote, “Avoid running any kind of unverified code from sources such as pirated software, videogame cheats, unverified plugins, and extensions.”

Sign up to Bybit and start trading with $30,050 in welcome gifts

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Bitcoin Steady as Fed Cuts Interest Rates for First Time Since December

Bitcoin Steady as Fed Cuts Interest Rates for First Time Since December

The post Bitcoin Steady as Fed Cuts Interest Rates for First Time Since December appeared on BitcoinEthereumNews.com. In brief The Federal Reserve had kept interest rates unchanged since last December. U.S. President Donald Trump has been hammering the Fed to cut rates. Crypto and other assets typically benefit from rate cuts that increase financial liquidity. The U.S. central bank, as widely expected, cut the federal funds rate by 0.25% Wednesday, amid recent signs that the economy was faltering and needed a boost—and under relentless pressure from President Donald Trump. Bitcoin and other major digital assets traded largely flat  in the immediate aftermath. The largest cryptocurrency by market capitalization was recently changing hands just above $116,000, up 0.2% over the past hour hours, according to crypto markets data provider CoinGecko. BTC rallied in recent days with investors possibly pricing in the anticipated decision. Ethereum, the second-largest cryptocurrency by market value, was trading at $4,501, flat over the same period. The Fed slashed the interest rate to a range between 4% and 4.25% after a downward revision in a Department of Labor report showing that the U.S had created 911,000 fewer jobs than initially reported for a year-long period ending in March, and other concerning economic signs. “Uncertainty about the economic outlook remains elevated,” the Fed noted in a statement. Those concerns outweighed the threat of inflation, which has risen to 2.9% on an annual basis, stubbornly above the bank’s longstanding 2% goal. Newly sworn-in governor Stephen Miran, a White House appointee, dissented from the decision, voting for a .50% rate cut. The Fed has a dual mission to keep inflation low and ensure full employment. In Telegram message to Decrypt, Noelle Acheson, the author of the Crypto Is Macro Now newsletter, wrote that the big deal wasn’t the expected rate cut but updated economic forecasts from Fed officials, showing that central bankers are “getting more nervous about the…
Share
BitcoinEthereumNews2025/09/18 14:49
Rumors Swirl: Is Saylor’s Strategy Quietly Backing Bitcoin and a Secret Meme Coin Presale?

Rumors Swirl: Is Saylor’s Strategy Quietly Backing Bitcoin and a Secret Meme Coin Presale?

Rumors hint Michael Saylor may back both Bitcoin and BullZilla’s meme coin presale, with $460K+ raised and 7,918% ROI projections making $BZIL a hot September buy.
Share
Blockchainreporter2025/09/18 01:15
Wormhole unveils strategic reserve to accumulate W token

Wormhole unveils strategic reserve to accumulate W token

The post Wormhole unveils strategic reserve to accumulate W token appeared on BitcoinEthereumNews.com. Key Takeaways Wormhole announced the creation of a strategic reserve aimed at supporting the value of its native W token. The reserve is part of a broader tokenomics initiative by Wormhole to enhance utility and value within its cross-chain protocol ecosystem. Wormhole introduced a strategic reserve designed to accumulate value into its W token, according to a blog post published today. The cross-chain protocol announced the initiative as part of its tokenomics strategy. The W token serves as Wormhole’s native digital asset within its interoperability ecosystem that connects multiple blockchain networks. Source: https://cryptobriefing.com/wormhole-strategic-reserve-w-token-value/
Share
BitcoinEthereumNews2025/09/17 23:49

Trade GOLD, Share 1,000,000 USDT

Trade GOLD, Share 1,000,000 USDTTrade GOLD, Share 1,000,000 USDT

0 fees, up to 1,000x leverage, deep liquidity