New SantaStealer malware steals data from browsers, crypto wallets

SantaStealer is a new malware-as-a-service information stealer advertised on Telegram, designed to evade detection by operating in memory. Rapid7’s analysis suggests it is a rebranded version of BluelineStealer with poor operational security and detection capabilities. #SantaStealer #BluelineStealer

Keypoints

  • SantaStealer targets sensitive data like browser passwords, cookies, and credit card info, as well as messaging and gaming apps.
  • The malware exfiltrates data in 10MB chunks via a hardcoded C2 endpoint, with multiple modules running simultaneously.
  • It features configurable options, including excluding CIS systems and delaying execution to evade detection.
  • Rapid7’s analysis indicates the samples are far from undetectable, revealing shortcomings in the developer’s operational security.
  • The malware uses an embedded executable to bypass Chrome’s encryption protections and can manipulate its distribution methods.

Read More: https://www.bleepingcomputer.com/news/security/new-santastealer-malware-steals-data-from-browsers-crypto-wallets/