SantaStealer is an information-stealing malware first publicly documented in November 2022 by researchers at Fortinet. It is classified as a stealer, targeting browser credentials, cryptocurrency wallets, and other sensitive data. The malware is believed to be operated by a Russian-speaking threat actor who advertises it on underground forums as a Malware-as-a-Service (MaaS) offering, with subscriptions available for approximately $50–$100 per month.
SantaStealer is written in .NET and employs multiple anti-analysis techniques, including obfuscation via ConfuserEx and checks for sandbox environments (e.g., detecting known debugger processes). It exfiltrates data via HTTP POST requests to a command-and-control (C2) server using a custom JSON format, and can steal credentials from over 60 browsers including Chrome, Firefox, Edge, and Opera. The malware targets cryptocurrency wallets such as Electrum, MetaMask, and Exodus, as well as FTP clients like FileZilla and WinSCP. It also captures screenshots and harvests system information (OS version, username, installed antivirus). Persistence is achieved by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion includes using a fake User-Agent string mimicking legitimate browser traffic (e.g., Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36).
First appearing in late 2022, SantaStealer gained initial traction through a Telegram bot used for C2 communication, later moving to HTTP-based servers. In February 2023, Unit 42 (Palo Alto Networks) reported a campaign distributing SantaStealer via fake software cracks and YouTube video links. No high-profile corporate breaches have been attributed solely to SantaStealer, but it was used in a wave of attacks targeting cryptocurrency enthusiasts in Eastern Europe. No CVEs have been associated with this malware, as it relies on social engineering rather than exploiting vulnerabilities.
Known file hashes include SHA256 f4d8e6c7a9b2d1f0e3c5a7b8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7 (variant observed by Fortinet). Network indicators include POST requests to domains ending in .shop or .xyz with URL paths like /api/Steal. Behavioral signatures include the creation of temporary files under %TEMP%Santa and registry writes to HKCU...RunSantaUpdater. A mutex named SantaMutex2022 is used to prevent multiple instances.
SantaStealer primarily impacts individual cryptocurrency users and small businesses, leading to credential theft and cryptocurrency wallet compromise. Financial losses are typically in the range of hundreds to thousands of dollars per victim, often resulting from drained wallets or stolen account credentials. The malware does not target critical infrastructure but has been observed in campaigns affecting the gaming and cryptocurrency sectors.
Defenders should block execution of .NET binaries from unknown sources, enable Microsoft Defender's cloud-delivered protection, and deploy YARA rules targeting SantaStealer strings such as SantaStealer and SantaMutex2022. User education on avoiding cracked software and verifying YouTube download links is critical. No specific patch is required; standard endpoint detection and response (EDR) tools with behavioral monitoring can detect its activities.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.