SantaStealer
- Malware type
- credential-stealer, spyware, trojan
- Last IoC activity
- 2026-07-21 22:45:11
- Profile updated
- 2026-07-07 15:19:09
Targeted industries: technology-and-telecommunications financial-services retail-and-hospitality
Context
According to Rapid7, this malware collects and exfiltrates sensitive documents, credentials, wallets, and data from a broad range of applications, and aims to operate entirely in-memory to avoid file-based detection. Stolen data is then compressed, split into 10 MB chunks, and sent to a C2 server over unencrypted HTTP.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Santa Stealer (report)
- rapid7.com — Tr Santastealer Is Coming To Town A New Ambitious Infostealer Advertised On Underground Forums (report)