• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
timbrestealer malware spreading via tax themed phishing scam targets it users

TimbreStealer Malware Spreading via Tax-themed Phishing Scam Targets IT Users

You are here: Home / General Cyber Security News / TimbreStealer Malware Spreading via Tax-themed Phishing Scam Targets IT Users
February 28, 2024

Mexican buyers have been targeted with tax-themed phishing lures at minimum since November 2023 to distribute a beforehand undocumented Windows malware called TimbreStealer.

Cisco Talos, which discovered the action, described the authors as expert and that the “threat actor has previously employed comparable techniques, methods and processes (TTPs) to distribute a banking trojan identified as Mispadu in September 2023.

Other than employing innovative obfuscation strategies to sidestep detection and be certain persistence, the phishing marketing campaign would make use of geofencing to solitary out buyers in Mexico, returning an innocuous blank PDF file in its place of the malicious just one if the payload sites are contacted from other locations.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Some of the notable evasive maneuvers include leveraging custom made loaders and direct procedure calls to bypass typical API checking, in addition to using Heaven’s Gate to execute 64-little bit code inside of a 32-bit course of action, an technique that was also not too long ago adopted by HijackLoader.

Cybersecurity

The malware will come with quite a few embedded modules for orchestration, decryption, and protection of the primary binary, when also managing a collection of checks to ascertain if it is really functioning a sandbox natural environment, the program language is not Russian, and the timezone is within just a Latin American location.

The orchestrator module also seems for information and registry keys to double-test that the device hasn’t been earlier infected, in advance of launching a payload installer part that shows a benign decoy file to the consumer, as it eventually triggers the execution of TimbreStealer’s main payload.

The payload is built to harvest a huge selection of info, which includes credential information from various folders, procedure metadata, and the URLs accessed, search for documents matching particular extensions, and verify the existence of distant desktop program.

TimbreStealer Malware

Cisco Talos said it identified overlaps with a Mispadu spam campaign noticed in September 2023, despite the fact that the goal industries of TimbreStealer are diverse and with a focus on production and transportation sectors.

The disclosure comes amid the emergence of a new edition of a different information stealer referred to as Atomic (aka AMOS), which is able of accumulating info from Apple macOS devices such as regional consumer account passwords, qualifications from Mozilla Firefox and Chromium-based mostly browsers, crypto wallet information and facts, and files of fascination, making use of an strange combination of Python and Apple Script code.

Cybersecurity

“The new variant drops and works by using a Python script to continue to be covert,” Bitdefender researcher Andrei Lapusneanu mentioned, noting the Apple Script block for collecting delicate data files from the victim’s computer reveals a “drastically superior degree of similarity” with the RustDoor backdoor.

It also follows the emergence of new stealer malware people this sort of as XSSLite, which was produced as portion of a malware development level of competition hosted by the XSS discussion board, even as present strains like Agent Tesla and Pony (aka Fareit or Siplog) ongoing to be made use of for information and facts theft and subsequent sale on stealer logs marketplaces like Exodus.

Identified this article appealing? Abide by us on Twitter  and LinkedIn to read much more unique content we submit.


Some areas of this article are sourced from:
thehackernews.com

Previous Post: «cybersecurity agencies warn ubiquiti edgerouter users of apt28's moobot threat Cybersecurity Agencies Warn Ubiquiti EdgeRouter Users of APT28’s MooBot Threat
Next Post: Superusers Need Super Protection: How to Bridge Privileged Access Management and Identity Management superusers need super protection: how to bridge privileged access management»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically
  • Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
  • China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats
  • China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
  • The MSP Cybersecurity Readiness Guide: Turning Security into Growth
  • CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers
  • Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery
  • CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
  • A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do
  • Google’s Built-In AI Defenses on Android Now Block 10 Billion Scam Messages a Month

Copyright © TheCyberSecurity.News, All Rights Reserved.