SantaStealer Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
December 15, 2025
Last Seen
February 7, 2026

SantaStealer is a malware family tracked across 6 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed December 15, 2025; most recent activity February 7, 2026.

Overview

SantaStealer is a credential and crypto-stealer malware family that targets Windows systems, extracting browser-stored passwords, crypto-wallet data, and other sensitive files. Marketed as inexpensive malware-as-a-service, it enables easy deployment by affiliates and remains widely used for credential theft and crypto theft. The variety of data exfiltrated and its ongoing activity make it a notable threat in the current threat landscape.

Related Threat Clusters

  • SantaStealer Malware Targets Passwords and Crypto Wallets

    SantaStealer is a new info-stealing malware being marketed as a service. It primarily targets web browsers, cryptocurrency wallets, and various applications to harvest sensitive information, including passwords. The…

    1 article · Updated January 6, 2026
  • SantaStealer Malware Compromises Windows Users' Passwords and Crypto Data

    The SantaStealer malware has emerged as a significant threat to Windows users during the holiday season, targeting sensitive files, credentials, and cryptocurrency wallet information. This malware exploits…

    2 articles · Updated December 25, 2025
  • SantaStealer Malware Targets Credentials and Crypto

    SantaStealer is a low-cost malware that targets various applications including browsers, wallets, and messaging apps to steal sensitive information such as credentials and cryptocurrency. It employs fourteen modules to…

    1 article · Updated January 17, 2026
  • SantaStealer Malware-as-a-Service Launching This Holiday Season

    A new malware-as-a-service called SantaStealer, previously known as BluelineStealer, is set to launch before the end of 2025. Advertised on Telegram and hacker forums, SantaStealer is designed to collect sensitive…

    4 articles · Updated December 16, 2025
  • Major Cybersecurity Incidents: $282M Crypto Theft and Blackmail of Pornhub Users

    A significant cybersecurity breach has led to the theft of $282 million in cryptocurrency. Additionally, Pornhub Premium users have been targeted in a blackmail scheme. Other incidents include the emergence of a new…

    9 articles · Updated January 24, 2026
  • Pornhub Premium Users Targeted by Blackmail Scheme

    Pornhub premium users have been blackmailed as part of a broader cybersecurity incident involving the SantaStealer crypto drainer. The attackers exploited vulnerabilities to steal sensitive information and demand ransom…

    2 articles · Updated December 20, 2025

Recent Intelligence Reports

  • Coinbase confirms data leak, record ransom in Russia and other cybersecurity news — Forklog · February 7, 2026
  • A $282m crypto theft, an exodus from Cambodia's scam camps, and other cybersecurity news — Forklog · January 24, 2026
  • SantaStealer is a cheap malware that steals credentials, crypto & more — Msn · January 17, 2026
  • SantaStealer malware still active, targeting passwords and crypto — Cyberguy · January 6, 2026
  • SantaStealer Malware Targets Windows Users, Stealing Passwords and Crypto Wallets — Techi · December 25, 2025
  • Pornhub premium users blackmailed, the SantaStealer crypto drainer, and other cybersecurity news — Forklog · December 20, 2025
  • SantaStealer bags credentials and crypto wallets — Theregister · December 17, 2025
  • SantaStealer stuffs credentials, crypto wallets into a brand new bag — Theregister · December 16, 2025

CVSS v3.1 Breakdown