logo

TimbreStealer Malware Spreading via Tax-themed Phishing Scam Targets IT Users

ID: 44f64069-48fd-5aed-a8eb-7dbf90563e71

STIX ID: report--44f64069-48fd-5aed-a8eb-7dbf90563e71

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-02-28

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cisco Talos identified a tax-themed phishing campaign active since at least November 2023 that distributes a new Windows information stealer called TimbreStealer to Mexican users; the campaign uses geofencing, custom loaders, direct syscalls and Heaven's Gate to evade detection and ensure persistence, and the malware harvests credentials, system metadata, browser URLs, and checks for remote desktop software while avoiding Russian locales and sandboxes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.