Skip to content

Infostealer

SantaStealer

According to Rapid7, this malware collects and exfiltrates sensitive documents, credentials, wallets, and data from a broad range of applications, and aims to operate entirely in-memory to avoid file-

SantaStealer is a Windows infostealer.

Background

Rapid7 reports that this malware gathers and exfiltrates sensitive documents, credentials, wallets, and information from a wide variety of applications, and tries to run wholly in memory to evade file-based detection. It compresses the stolen data, breaks it into 10 MB pieces, and ships it to a C2 server over plaintext HTTP.


Source: Malpedia (Fraunhofer FKIE).