SantaStealer is a malware family tracked across 6 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed December 15, 2025; most recent activity February 7, 2026.
SantaStealer is a credential and crypto-stealer malware family that targets Windows systems, extracting browser-stored passwords, crypto-wallet data, and other sensitive files. Marketed as inexpensive malware-as-a-service, it enables easy deployment by affiliates and remains widely used for credential theft and crypto theft. The variety of data exfiltrated and its ongoing activity make it a notable threat in the current threat landscape.
SantaStealer is a new info-stealing malware being marketed as a service. It primarily targets web browsers, cryptocurrency wallets, and various applications to harvest sensitive information, including passwords. The…
The SantaStealer malware has emerged as a significant threat to Windows users during the holiday season, targeting sensitive files, credentials, and cryptocurrency wallet information. This malware exploits…
SantaStealer is a low-cost malware that targets various applications including browsers, wallets, and messaging apps to steal sensitive information such as credentials and cryptocurrency. It employs fourteen modules to…
A new malware-as-a-service called SantaStealer, previously known as BluelineStealer, is set to launch before the end of 2025. Advertised on Telegram and hacker forums, SantaStealer is designed to collect sensitive…
A significant cybersecurity breach has led to the theft of $282 million in cryptocurrency. Additionally, Pornhub Premium users have been targeted in a blackmail scheme. Other incidents include the emergence of a new…
Pornhub premium users have been blackmailed as part of a broader cybersecurity incident involving the SantaStealer crypto drainer. The attackers exploited vulnerabilities to steal sensitive information and demand ransom…