SantaStealer malware targets crypto wallets and browsers

Source Cryptopolitan

SantaStealer is a new information-stealing malware that targets crypto wallets. The malware-as-a-service (MaaS) extracts private data linked to any type of crypto.

Researchers at Rapid7 say that SantaStealer is a rebrand of another infostealer called BluelineStealer. The developer of SantaStealer is rumored to be preparing a wider launch before the year ends.

At the moment, the malware is advertised on Telegram and hacker forums, and offered as a subscription service. Basic access costs $175 per month, while Premium access is more expensive and costs $300.

The SantaStealer malware developers claim enterprise-level capability with antivirus bypasses and corporate network access.

SantaStealer targets crypto wallets

Crypto wallets are the main focus of SantaStealer. The malware targets crypto wallet apps like Exodus and browser extensions like MetaMask. It is designed to extract private data linked to digital assets.

The malware doesn’t stop there. It also steals browser data, including passwords, cookies, browsing history, and saved credit card information. Messaging platforms such as Telegram and Discord are targeted as well. Steam data and local documents are included. The malware can also capture desktop screenshots.

To do this, it drops or loads an embedded executable. That executable decrypts and injects code into the browser. This allows access to protected keys.

SantaStealer zeroes in on crypto wallets as main target.
SantaStealer advertisement in Russian and English. Source: Rapid7.

SantaStealer runs many data collection modules simultaneously. Each module operates in its own thread. Stolen data is written to memory, compressed into ZIP files, and exfiltrated in 10MB chunks. The data is sent to a hardcoded command-and-control server over port 6767.

To reach wallet data stored in browsers, the malware bypasses Chrome’s App-Bound Encryption, which was introduced in July of 2024. According to Rapid7, multiple info-stealers have already defeated it.

The malware is marketed as advanced, with total evasion. But Rapid7 security researchers say the malware does not match those claims. Current samples are easy to analyze, and they expose symbols and readable strings. This suggests rushed development and weak operational security.

“The anti-analysis and stealth capabilities of the stealer advertised in the web panel remain very basic and amateurish, with only the third-party Chrome decryptor payload being somewhat hidden,” wrote Milan Spinka from Rapid7.

The affiliate panel of SantaStealer is polished. Operators can customize builds, and they can steal everything or focus only on wallet and browser data. The options also allow operators to exclude the Commonwealth of Independent States (CIS) region and delay execution.

SantaStealer has not yet spread on a large scale, and its delivery method remains unclear. Recent campaigns favor ClickFix attacks since victims are tricked into pasting malicious commands into Windows terminals.

According to the researchers, other malware delivery paths remain common. These include phishing emails, pirated software, torrents, malvertising, and deceptive YouTube comments.

Security researchers advise crypto users to stay alert and avoid unknown links and attachments.

Spinka wrote, “Avoid running any kind of unverified code from sources such as pirated software, videogame cheats, unverified plugins, and extensions.”

Want your project in front of crypto’s top minds? Feature it in our next industry report, where data meets impact.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
US Dollar's Decline Predicted in 2026: Morgan Stanley's Outlook on Currency VolatilityMorgan Stanley forecasts a 5% drop in the dollar by mid-2026, attributed to continued Fed rate cuts. A recovery may follow as growth improves and funding currency dynamics shift favorably toward the euro and Swiss franc.
Author  Mitrade
Nov 25, Tue
Morgan Stanley forecasts a 5% drop in the dollar by mid-2026, attributed to continued Fed rate cuts. A recovery may follow as growth improves and funding currency dynamics shift favorably toward the euro and Swiss franc.
placeholder
Gold's Historic 2025 Rally: Can the Momentum Last Through 2026?Following a historic surge in 2025 that saw prices climb over 60% and break records more than 50 times, gold investors are now looking ahead to assess whether the precious metal can sustain its momentum into 2026. Despite outperforming most major asset classes and heading for its best annual performance since 1979, analysts are divided on the outlook—with some seeing further room for gains and others cautioning that risks are rising.
Author  Mitrade
Dec 09, Tue
Following a historic surge in 2025 that saw prices climb over 60% and break records more than 50 times, gold investors are now looking ahead to assess whether the precious metal can sustain its momentum into 2026. Despite outperforming most major asset classes and heading for its best annual performance since 1979, analysts are divided on the outlook—with some seeing further room for gains and others cautioning that risks are rising.
placeholder
XRP Spot ETFs Notch 30 Straight Days of Inflows, Bucking Wider Crypto TrendSince their debut on November 13, U.S.-listed spot exchange-traded funds (ETFs) for XRP have recorded net inflows for 30 consecutive trading days, a steady performance that stands in contrast to the more volatile flows seen in larger bitcoin and ether funds.
Author  Mitrade
Dec 15, Mon
Since their debut on November 13, U.S.-listed spot exchange-traded funds (ETFs) for XRP have recorded net inflows for 30 consecutive trading days, a steady performance that stands in contrast to the more volatile flows seen in larger bitcoin and ether funds.
placeholder
Cryptocurrencies Extend Losses as Year-End Caution and Thinning Liquidity Weigh on MarketThe cryptocurrency market declined on Monday, mirroring a pullback in global risk assets as investors turned cautious ahead of key U.S. economic data. The broad-based retreat highlighted thinning liquidity and growing risk aversion across financial markets as the year draws to a close.
Author  Mitrade
Dec 16, Tue
The cryptocurrency market declined on Monday, mirroring a pullback in global risk assets as investors turned cautious ahead of key U.S. economic data. The broad-based retreat highlighted thinning liquidity and growing risk aversion across financial markets as the year draws to a close.
placeholder
BOJ Set to Hike Rates Amid Inflation Pressures and Yen Weakness The Bank of Japan is expected to raise its benchmark interest rate to 0.75% on December 19, marking its first increase since early 2025, amidst ongoing inflation and a weakening yen. Analysts predict additional hikes in 2026 as the central bank navigates renewed monetary policy normalization under Governor Kazuo Ueda.
Author  Mitrade
Dec 18, Thu
The Bank of Japan is expected to raise its benchmark interest rate to 0.75% on December 19, marking its first increase since early 2025, amidst ongoing inflation and a weakening yen. Analysts predict additional hikes in 2026 as the central bank navigates renewed monetary policy normalization under Governor Kazuo Ueda.
goTop
quote