HomeSecuritySantaStealer: New MaaS Infostealer Fails Its “Undetectable” Hype

SantaStealer: New MaaS Infostealer Fails Its “Undetectable” Hype

A newly advertised malware-as-a-service (MaaS) information stealer dubbed SantaStealer is making the rounds on Telegram and underground forums, promising “in-memory” operation designed to evade file-based detection. But according to Rapid7, the current reality doesn’t match the marketing.

Rapid7 says SantaStealer appears to be a rebrand of “BluelineStealer”, and while the actor pitches it as stealthy and hard to analyze, researchers found the samples they reviewed were “far from undetectable” and even shipped with telltale development artifacts like symbol names and unencrypted strings—an operational security slip that makes analysis easier, not harder.

Notably, Rapid7 also updated its reporting to say SantaStealer’s official Telegram channel has announced a release, which suggests the operators consider it ready for wider use—even if the observed builds still look rough around the edges.

Pricing and the affiliate model

SantaStealer is being sold as a subscription service with two tiers:

  • Basic: $175/month
  • Premium: $300/month

Rapid7 says it was able to analyze multiple samples and gain access to the affiliate web panel, which lets customers configure builds with different targeting scopes—from “grab everything” bundles to leaner payloads focused on specific data types.

What SantaStealer does in practice

Rapid7’s analysis describes a modular stealer built around 14 distinct data-collection modules, each running in its own thread. The workflow is designed to minimize obvious footprints during collection, but it’s not truly “fileless” in practice:

  • Data is gathered and staged in memory during collection
  • It’s then archived into a ZIP (Rapid7 observed a Log.zip written to the TEMP directory)
  • Exfiltration occurs in 10MB chunks to a hardcoded command-and-control endpoint using port 6767

The module set targets common high-value theft categories, including browser-stored credentials and session data (passwords, cookies, history, saved payment data), plus app and platform data (including Telegram, Discord, and Steam). Rapid7 also notes screenshot capability and collection from local files such as documents/notes.

Chrome’s newer protections are already being worked around

One of the more important technical notes is SantaStealer’s attempt to bypass Chrome’s Application-Bound / AppBound encryption protections—introduced by Google in July 2024—by using an embedded executable. Rapid7 notes this isn’t unique to SantaStealer; multiple active stealers have been working on similar bypass approaches.

CIS exclusions and execution delays

Rapid7 also highlights configuration options that let operators avoid certain targets and reduce exposure:

  • A CIS avoidance mechanism (Rapid7 observed a check that can key off keyboard layout; if triggered, the sample can drop an empty file named “CIS” and exit)
  • Delayed execution options to introduce inactivity windows and complicate incident timelines

Interestingly, Rapid7 notes the CIS behavior may be configurable rather than strictly hardcoded, which is a bit unusual for this category.

How it might spread

Because SantaStealer’s real-world distribution scale is still unclear—even after the actor announced release—Rapid7 doesn’t pin it to a single delivery method. That said, the broader infostealer ecosystem in 2025 has heavily leaned on social engineering and “fake fix” style lures (often called ClickFix), where victims are tricked into running commands that fetch a payload.

What defenders should do

Rapid7’s guidance boils down to reducing the odds users ever execute the initial payload:

  • Treat unexpected links/attachments with suspicion
  • Avoid running unverified code and installers (including “helpful” scripts and tools)
  • Be cautious with browser extensions and downloads from public repositories unless you can validate provenance
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular

POPULAR TAGS

- Advertisment -