SantaStealer Malware: A New Holiday-Themed Infostealer Targeting Business Credentials
Russian Threat Actors Launch Malware-As-A-Service Credential Stealer – Phishing Emails And Fake Verification Prompts Distribute New Malware Threat
A cheap new infostealer sold on Russian forums grabs browser credentials, session tokens, and crypto wallets from Chrome and Edge. Houston small businesses are exactly the soft target it was built for - and the defense is a short, specific list.
SantaStealer is an infostealer - malware built to quietly copy the credentials, session tokens, and wallet data already sitting on a computer, then ship them to an attacker. Infostealer malware protection means closing the paths those credentials travel, not chasing one strain by name.
Rapid7 Labs documented SantaStealer in December 2025 as a new malware-as-a-service stealer advertised on Russian-speaking forums, rented for roughly $175 to $300 per month, and rebranded from an earlier tool called BluelineStealer. It targets Chromium browsers like Chrome and Edge, carries a component to bypass Chrome's App Bound Encryption, and pulls saved passwords, cookies, credit card data, session tokens from apps like Telegram and Discord, and cryptocurrency wallets. The name will change. The behavior will not. That is why this guide is a defense checklist against infostealers as a class, not a profile of one holiday-themed logo. Houston runs on small businesses - law offices, CPA practices, medical clinics, energy-services firms - and infostealers treat every one of them as a soft target.
What Does an Infostealer Like SantaStealer Actually Grab?
Not a scan of your files - a targeted sweep of the exact places browsers and apps stash credentials and live sessions.
An infostealer harvests three things that matter most to a business: saved browser credentials, active session tokens and cookies, and cryptocurrency wallet data - then packages them and sends them to an attacker, often within seconds of running.
SantaStealer is built as a modular, multi-threaded stealer, which is a fancy way of saying it runs a set of small jobs at once, each aimed at a different data store. Rapid7 counted 14 stealing modules. According to Rapid7, the collected data is zipped, split into 10 MB chunks, and sent to attacker servers over plain HTTP. In practice, the categories below are what turn one infected laptop into a business-wide problem.
- Saved browser passwords and autofill. Chrome and Edge store logins, addresses, phone numbers, and card details. A stealer copies that vault straight off the disk - which is why "save password?" is a business risk, not a convenience.
- Session cookies and tokens. These keep you logged into email, banking, and SaaS without re-entering a password. Steal a live session and an attacker can ride it into the account, sometimes without triggering MFA at all.
- Cryptocurrency wallets. The stealer scrapes wallet addresses, private keys, and seed phrases. Any business holding digital assets can lose them with no way to reverse the transfer.
- App and messaging data. Telegram, Discord, and Steam session data get pulled - useful for account takeover and for reaching further into a company through a trusted account.
What Is the Infostealer Defense Checklist for a Small Business?
Seven controls that close the credential-theft paths infostealers depend on. Put these in place and a stolen laptop stops being a stolen company.
Infostealer malware protection comes down to a credential-theft defense checklist: phishing-resistant MFA and passkeys, session-token protections, EDR on every device, browsers that do not store passwords, fast patching, blocked malvertising and fake-verification lures, and a team trained to spot them.
- Move to phishing-resistant MFA and passkeys. Push-approval MFA still helps, but passkeys and FIDO2 security keys are bound to the real site and cannot be replayed from a stolen session the way a reused cookie can. Turn them on for email, banking, and admin accounts first.
- Protect the session, not just the login. Enable token-binding and conditional-access features in Microsoft 365 or Google Workspace so a session cookie stolen off one device is rejected from an attacker's machine. Shorten session lifetimes on high-value apps.
- Run EDR on every endpoint. Infostealers like SantaStealer try to operate in memory to dodge signature antivirus. Behavior-based endpoint detection and response is what flags a process reading the browser credential store and beaconing out.
- Stop storing passwords in the browser. Move the team to a dedicated password manager and turn off Chrome and Edge password saving by policy. If the browser vault is empty, the module built to steal it comes back with nothing.
- Patch browsers and operating systems on a schedule. SantaStealer ships a bypass for a mid-2024 Chrome encryption feature; an out-of-date browser is a wider door. Keep Chrome, Edge, Windows, and applications current automatically.
- Block the delivery paths. Infostealers arrive through malvertising, pirated software, game cheats, and fake "verify you are human" prompts that tell users to paste a command. Filter DNS and web traffic, restrict software installs, and block script-paste lures.
- Train the team on fake verification and support scams. The human element is still the trigger. Staff who recognize a bogus CAPTCHA or a fake IT-support instruction to run a command are the control that stops the infection before any module runs.
Why Are Houston Small Businesses the Target for Rented Infostealers?
A malware-as-a-service model means the buyer does not need skill - just a target with saved passwords and no one watching the endpoints.
Houston small businesses are prime targets because the malware-as-a-service model lets any buyer, skilled or not, rent SantaStealer for a few hundred dollars a month and aim it at firms that store passwords in browsers and lack full-time security staff.
The rental price is the point. When a working infostealer costs less than a monthly software subscription, the attacker pool stops being elite hackers and becomes anyone with a credit card and a grudge. That widens exposure for the businesses that make up the Houston metro: professional-services firms holding client data, medical practices where a stolen login is also a HIPAA problem, and energy-services companies whose credentials can reach into larger partner and infrastructure networks. None of those firms usually run a security operations center. That gap - valuable credentials plus thin monitoring - is exactly the soft target the malware-as-a-service model is priced to hit.
Here is the local reality. A stolen session token from a Katy CPA practice or a Sugar Land law office is not a nuisance; it can be the front door to client tax records, escrow instructions, or privileged case files. The defense checklist above is affordable for a 10 to 200 person firm precisely because most of it is configuration and monitoring, not a pile of new products - which is what a local managed IT partner sets up and keeps running.
Owners still picture a hacker in a hoodie targeting them by name. That is not what an infostealer is. It is a rented tool that copies the passwords your browser already saved and the session that keeps you logged in - and then someone logs in as you. Empty the browser vault, put EDR on every laptop, and move to passkeys, and you have taken away the three things it came for.
Infostealer Defense, Set Up and Watched for You
CinchOps stands up the full credential-theft defense checklist for Houston-area SMBs - phishing-resistant MFA and passkeys, EDR on every endpoint, browser password lockdown, patching, DNS and web filtering, and awareness training - and monitors it so a stolen laptop does not become a stolen company. It is part of our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →How CinchOps Helps Houston SMBs Defend Against Infostealers
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area.
CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. Against infostealers like SantaStealer, that means the checklist above set up correctly and kept running:
- Identity and session hardening. Phishing-resistant MFA and passkeys enforced on the accounts that matter, plus conditional access that rejects a stolen session from an unknown device.
- EDR and endpoint control. Behavior-based detection on every device, watched around the clock, to catch a stealer reading the credential store before data leaves the building.
- Browser and password hygiene. Browser password storage turned off by policy and a business password manager rolled out, so the vault a stealer targets is empty.
- Filtering, patching, and training. DNS and web filtering to block malvertising and fake-verification lures, scheduled patching for browsers and systems, and training so the team spots the trick that starts an infection.
We serve businesses across the Houston area, including Houston, Katy, and Sugar Land, and we know what a law firm, CPA practice, or energy-services firm stands to lose when a single set of credentials walks out the door. You do not need to know whether SantaStealer specifically is on your network to take this seriously - the controls that stop it are the same ones that stop the next stealer with a different name. If you run a small business in the Houston metro, talk to CinchOps for a security assessment and a clear read on which of these controls you are missing.
Frequently Asked Questions
What is SantaStealer malware?
SantaStealer is a malware-as-a-service infostealer that Rapid7 Labs documented in December 2025. Rented for roughly $175 to $300 per month on Russian-speaking forums, it steals saved browser passwords, cookies, session tokens, and cryptocurrency wallets from Chromium browsers like Chrome and Edge, and was rebranded from an earlier tool called BluelineStealer.
How do you protect a business from infostealer malware?
Follow a credential-theft defense checklist rather than chasing one strain: phishing-resistant MFA and passkeys, session-token protection, EDR on every device, a password manager instead of browser-stored passwords, fast patching, and DNS or web filtering to block malvertising and fake verification prompts. Layered controls close the paths every infostealer uses.
Can an infostealer bypass multi-factor authentication?
It can, indirectly. Infostealers grab session cookies and tokens that keep you logged in, and reusing a live session can let an attacker skip the MFA prompt entirely. Phishing-resistant MFA, passkeys, and token-binding or conditional-access controls are what defeat stolen-session reuse that ordinary MFA does not.
Are Houston small businesses really at risk from SantaStealer?
Yes. The malware-as-a-service model lets any buyer rent the stealer cheaply and aim it at firms that store passwords in browsers and lack full-time security staff. Houston professional-services, medical, and energy-services SMBs fit that profile, and a stolen login can also mean a HIPAA or client-confidentiality problem.
Should employees stop saving passwords in Chrome and Edge?
Yes. Browser-stored passwords are a primary target for infostealers, which copy the saved vault directly. Move staff to a dedicated password manager and turn off browser password saving by policy. If the browser vault is empty, the stealer module built to grab it comes back with nothing useful.
Discover More
Sources
- Rapid7 Labs, SantaStealer is Coming to Town: A New, Ambitious Infostealer Advertised on Underground Forums (December 2025)
- Hive Pro, SantaStealer: An Emerging MaaS Infostealer Ahead of Its 2025 Debut
- Broadcom Symantec Security Center, SantaStealer - a new MaaS infostealer
- CISA, guidance on infostealer and credential-theft defenses