• bitcoinBitcoin (BTC) $ 88,205.00
  • ethereumEthereum (ETH) $ 2,966.54
  • tetherTether (USDT) $ 0.999768
  • bnbBNB (BNB) $ 852.08
  • xrpXRP (XRP) $ 1.92
  • usd-coinUSDC (USDC) $ 0.999713
  • solanaSolana (SOL) $ 125.02
  • tronTRON (TRX) $ 0.285676
  • staked-etherLido Staked Ether (STETH) $ 2,967.72
  • dogecoinDogecoin (DOGE) $ 0.130563
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • cardanoCardano (ADA) $ 0.364136
  • whitebitWhiteBIT Coin (WBT) $ 57.57
  • bitcoin-cashBitcoin Cash (BCH) $ 583.10
  • wrapped-stethWrapped stETH (WSTETH) $ 3,626.62
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 88,154.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,222.01
  • usdsUSDS (USDS) $ 0.999727
  • wrapped-eethWrapped eETH (WEETH) $ 3,218.25
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999808
  • chainlinkChainlink (LINK) $ 12.42
  • moneroMonero (XMR) $ 469.59
  • wethWETH (WETH) $ 2,969.64
  • leo-tokenLEO Token (LEO) $ 8.00
  • zcashZcash (ZEC) $ 434.06
  • stellarStellar (XLM) $ 0.215247
  • hyperliquidHyperliquid (HYPE) $ 24.05
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 88,400.00
  • ethena-usdeEthena USDe (USDE) $ 0.998674
  • litecoinLitecoin (LTC) $ 76.63
  • suiSui (SUI) $ 1.43
  • avalanche-2Avalanche (AVAX) $ 12.15
  • hedera-hashgraphHedera (HBAR) $ 0.111167
  • susdssUSDS (SUSDS) $ 1.08
  • usdt0USDT0 (USDT0) $ 0.999332
  • shiba-inuShiba Inu (SHIB) $ 0.000007
  • daiDai (DAI) $ 0.998792
  • canton-networkCanton (CC) $ 0.110647
  • uniswapUniswap (UNI) $ 6.29
  • paypal-usdPayPal USD (PYUSD) $ 0.999694
  • mantleMantle (MNT) $ 1.17
  • crypto-com-chainCronos (CRO) $ 0.094734
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.132827
  • the-open-networkToncoin (TON) $ 1.47
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • polkadotPolkadot (DOT) $ 1.80
  • usd1-wlfiUSD1 (USD1) $ 0.998969
  • aaveAave (AAVE) $ 175.51
  • rainRain (RAIN) $ 0.007609
  • bitget-tokenBitget Token (BGB) $ 3.47
  • memecoreMemeCore (M) $ 1.37
  • tether-goldTether Gold (XAUT) $ 4,356.24
  • okbOKB (OKB) $ 107.15
  • falcon-financeFalcon USD (USDF) $ 0.998013
  • bittensorBittensor (TAO) $ 219.65
  • nearNEAR Protocol (NEAR) $ 1.50
  • ethereum-classicEthereum Classic (ETC) $ 12.22
  • jito-staked-solJito Staked SOL (JITOSOL) $ 156.16
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,974.49
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.205719
  • internet-computerInternet Computer (ICP) $ 3.11
  • pepePepe (PEPE) $ 0.000004
  • aster-2Aster (ASTER) $ 0.706520
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • ethenaEthena (ENA) $ 0.208305
  • midnight-3Midnight (NIGHT) $ 0.093483
  • htx-daoHTX DAO (HTX) $ 0.000002
  • hash-2Provenance Blockchain (HASH) $ 0.029047
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.53
  • pax-goldPAX Gold (PAXG) $ 4,361.28
  • global-dollarGlobal Dollar (USDG) $ 0.999801
  • skySky (SKY) $ 0.063214
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • kucoin-sharesKuCoin (KCS) $ 10.73
  • ripple-usdRipple USD (RLUSD) $ 0.999736
  • bfusdBFUSD (BFUSD) $ 0.999232
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999820
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • worldcoin-wldWorldcoin (WLD) $ 0.506255
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,422.60
  • ondo-financeOndo (ONDO) $ 0.388335
  • kaspaKaspa (KAS) $ 0.045591
  • aptosAptos (APT) $ 1.59
  • gatechain-tokenGate (GT) $ 10.24
  • binance-staked-solBinance Staked SOL (BNSOL) $ 135.74
  • wbnbWrapped BNB (WBNB) $ 854.25
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.107558
  • pump-funPump.fun (PUMP) $ 0.001918
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,148.76
  • arbitrumArbitrum (ARB) $ 0.186700
  • official-trumpOfficial Trump (TRUMP) $ 5.05
  • algorandAlgorand (ALGO) $ 0.112067
  • ignition-fbtcFunction FBTC (FBTC) $ 88,066.00
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 88,560.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 88,248.00
  • filecoinFilecoin (FIL) $ 1.29
  • cosmosCosmos Hub (ATOM) $ 1.94
  • nexoNEXO (NEXO) $ 0.932327
  • flare-networksFlare (FLR) $ 0.011466
  • vechainVeChain (VET) $ 0.010520
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,180.75
  • usdtbUSDtb (USDTB) $ 0.999230
  • xdce-crowd-saleXDC Network (XDC) $ 0.045375
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.93
  • ousgOUSG (OUSG) $ 113.70
  • usddUSDD (USDD) $ 0.999713
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999747
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • beldexBeldex (BDX) $ 0.096640
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 87,966.00
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,214.56
  • sei-networkSei (SEI) $ 0.108837
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999800
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • clbtcclBTC (CLBTC) $ 88,238.00
  • bonkBonk (BONK) $ 0.000008
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,168.02
  • render-tokenRender (RENDER) $ 1.26
  • usdaiUSDai (USDAI) $ 1.00
  • wrapped-flareWrapped Flare (WFLR) $ 0.011467
  • morphoMorpho (MORPHO) $ 1.20
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999819
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.23
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.86
  • jupiter-exchange-solanaJupiter (JUP) $ 0.190994
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,969.37
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 144.55
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,126.55
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008999
  • myx-financeMYX Finance (MYX) $ 2.86
  • usual-usdUsual USD (USD0) $ 0.997791
  • story-2Story (IP) $ 1.58
  • tbtctBTC (TBTC) $ 88,274.00
  • optimismOptimism (OP) $ 0.270073
  • bridged-wrapped-ether-pundi-aifx-omnilayerBridged Wrapped Ether (Pundi AIFX Omnilayer) (WETH) $ 35,382,014.00
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,968.44
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999201
  • curve-dao-tokenCurve DAO (CRV) $ 0.345922
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • ghoGHO (GHO) $ 0.998306
  • true-usdTrueUSD (TUSD) $ 0.995836
  • dashDash (DASH) $ 38.51
  • lido-daoLido DAO (LDO) $ 0.534846
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.205424
  • gtethGTETH (GTETH) $ 2,970.62
  • tezosTezos (XTZ) $ 0.440519
  • ether-fiEther.fi (ETHFI) $ 0.722018
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.704105
  • merlin-chainMerlin Chain (MERL) $ 0.423975
  • injective-protocolInjective (INJ) $ 4.61
  • newton-projectAB (AB) $ 0.004985
  • blockstackStacks (STX) $ 0.250389
  • aerodrome-financeAerodrome Finance (AERO) $ 0.495773
  • spx6900SPX6900 (SPX) $ 0.473581
  • stader-ethxStader ETHx (ETHX) $ 3,199.35
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,166.01
  • msolMarinade Staked SOL (MSOL) $ 168.14
  • pippinpippin (PIPPIN) $ 0.426964
  • audieraAudiera (BEAT) $ 3.00
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.200837
  • usdbUSDB (USDB) $ 0.988665
  • swethSwell Ethereum (SWETH) $ 3,278.06
  • sbtc-2sBTC (SBTC) $ 89,465.00
  • celestiaCelestia (TIA) $ 0.460698
  • justJUST (JST) $ 0.039987
  • starknetStarknet (STRK) $ 0.078715
  • flokiFLOKI (FLOKI) $ 0.000041
  • the-graphThe Graph (GRT) $ 0.036618
  • bittorrentBitTorrent (BTT) $ 0.00000040
  • lorenzo-wrapped-bitcoinLorenzo Wrapped Bitcoin (ENZOBTC) $ 90,454.00
  • sun-tokenSun Token (SUN) $ 0.020299
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,308.07
  • syrupMaple Finance (SYRUP) $ 0.330050
  • doublezeroDoubleZero (2Z) $ 0.106798
  • bitcoin-svBitcoin SV (BSV) $ 18.47
  • iotaIOTA (IOTA) $ 0.087782
  • chilizChiliz (CHZ) $ 0.036298
  • ethereum-name-serviceEthereum Name Service (ENS) $ 9.60
  • conflux-tokenConflux (CFX) $ 0.070496
  • telcoinTelcoin (TEL) $ 0.003793
  • olympusOlympus (OHM) $ 21.98
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 88,395.00
  • apenftAINFT (NFT) $ 0.00000035
  • euro-coinEURC (EURC) $ 1.17
  • kaiaKaia (KAIA) $ 0.059296
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.829923
  • pyth-networkPyth Network (PYTH) $ 0.059390
  • dogwifcoindogwifhat (WIF) $ 0.338509
  • cap-usdCap USD (CUSD) $ 0.999119
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.130730
  • crvusdcrvUSD (CRVUSD) $ 0.998656
  • resolv-usrResolv USR (USR) $ 0.999993
  • kinesis-goldKinesis Gold (KAU) $ 139.98
  • usxUSX (USX) $ 0.999367
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.12
  • gnosisGnosis (GNO) $ 121.19
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,976.85
  • basic-attention-tokenBasic Attention (BAT) $ 0.208913

SantaStealer malware targets crypto wallets and browsers

0 2

SantaStealer malware targets crypto wallets and browsers

SantaStealer is a new information-stealing malware that targets crypto wallets. The malware-as-a-service (MaaS) extracts private data linked to any type of crypto.

Researchers at Rapid7 say that SantaStealer is a rebrand of another infostealer called BluelineStealer. The developer of SantaStealer is rumored to be preparing a wider launch before the year ends.

At the moment, the malware is advertised on Telegram and hacker forums, and offered as a subscription service. Basic access costs $175 per month, while Premium access is more expensive and costs $300.

The SantaStealer malware developers claim enterprise-level capability with antivirus bypasses and corporate network access.

SantaStealer targets crypto wallets

Crypto wallets are the main focus of SantaStealer. The malware targets crypto wallet apps like Exodus and browser extensions like MetaMask. It is designed to extract private data linked to digital assets.

The malware doesn’t stop there. It also steals browser data, including passwords, cookies, browsing history, and saved credit card information. Messaging platforms such as Telegram and Discord are targeted as well. Steam data and local documents are included. The malware can also capture desktop screenshots.

To do this, it drops or loads an embedded executable. That executable decrypts and injects code into the browser. This allows access to protected keys.

SantaStealer malware targets crypto wallets and browsers

SantaStealer advertisement in Russian and English. Source: Rapid7.

SantaStealer runs many data collection modules simultaneously. Each module operates in its own thread. Stolen data is written to memory, compressed into ZIP files, and exfiltrated in 10MB chunks. The data is sent to a hardcoded command-and-control server over port 6767.

To reach wallet data stored in browsers, the malware bypasses Chrome’s App-Bound Encryption, which was introduced in July of 2024. According to Rapid7, multiple info-stealers have already defeated it.

The malware is marketed as advanced, with total evasion. But Rapid7 security researchers say the malware does not match those claims. Current samples are easy to analyze, and they expose symbols and readable strings. This suggests rushed development and weak operational security.

“The anti-analysis and stealth capabilities of the stealer advertised in the web panel remain very basic and amateurish, with only the third-party Chrome decryptor payload being somewhat hidden,” wrote Milan Spinka from Rapid7.

The affiliate panel of SantaStealer is polished. Operators can customize builds, and they can steal everything or focus only on wallet and browser data. The options also allow operators to exclude the Commonwealth of Independent States (CIS) region and delay execution.

SantaStealer has not yet spread on a large scale, and its delivery method remains unclear. Recent campaigns favor ClickFix attacks since victims are tricked into pasting malicious commands into Windows terminals.

According to the researchers, other malware delivery paths remain common. These include phishing emails, pirated software, torrents, malvertising, and deceptive YouTube comments.

Security researchers advise crypto users to stay alert and avoid unknown links and attachments.

Spinka wrote, “Avoid running any kind of unverified code from sources such as pirated software, videogame cheats, unverified plugins, and extensions.”

Source

Leave A Reply

Your email address will not be published.