ECONOMY & WORK
MONEY 101
NEWS
PERSONAL FINANCE
NET WORTH
About Us Contact Us Privacy Policy Terms of Use DMCA Opt-out of personalized ads
© Copyright 2023 Market Realist. Market Realist is a registered trademark. All Rights Reserved. People may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.
MARKETREALIST.COM / ECONOMY & WORK

New Information Stealer Malware 'TimbreStealer' Is Targeting Mexican Users: Report

They lure victims to download a new obfuscated information stealer that the company is calling "TimbreStealer".
PUBLISHED MAR 1, 2024
Cover Image Source: Hacker on Laptop | Sora Shimazak | Pexels
Cover Image Source: Hacker on Laptop | Sora Shimazak | Pexels

An information stealer malware has emerged to be one of the biggest threats recently. This malware has been proven dangerous for organizations and individuals alike. 

Cisco Talos, an Intelligence Group, discovered a new campaign operated by a threat actor distributing a previously unknown malware called "TimbreStealer." The group describes the authors as skilled and that the "threat actor has previously used similar tactics, techniques, and procedures (TTPs)" to pull off a banking fraud known as Mispadu in September 2023, as per the report.

The phishing campaign is pretty advanced and can employ sophisticated techniques that sidestep detection and ensure persistence. This particular phishing campaign makes use of geofencing to target users in Mexico, as mentioned in the report.



 

They lure the victims to download a new obfuscated information stealer that the company is calling "TimbreStealer". They also use phishing emails with financial schemes directing the people to a shady website where the payload is hosted. Some of the evasive techniques used include leveraging custom loaders and system calls to bypass the main API monitoring. They also use Heaven's Gate to execute 64-bit code within a 32-bit process which is a pretty well-known approach.

Talos also saw other distribution campaigns that have been conducted by this actor since 2023. The current spam run mainly used Mexico's digital tax receipt standard called CDFI. This malware has many embedded modules for decryption and protection of the main binary as well as orchestration. The malware can also run a series of checks to determine if it's running a sandbox environment. It was also seen that the orchestrator module took files and registry keys to double-check that the machine hadn't been previously attacked before it finally launched a payload installer that displayed a file to the user and then triggered the execution of TimbreStealer's primary payload.

Getty Images | Photo by Manuel Medir
Getty Images | Photo by Manuel Medir

This payload is specifically designed to get a range of data starting from credential information to system metadata and more. The payload is also capable of looking for files that match the specific extension and verifying the presence of remote desktop software. 

The orchestrator has four other encrypted sub-modules within it. "Each stripped DLL is loaded by a custom shellcode loader from submodule #0 (IDX = 0). Execution is transferred to this shellcode through a Heaven’s Gate stub using the ZwCreateThreadEx API," the analysis reads.

TimbreStealer is also capable of collecting OS information, and it does that by using the Windows Management Instrumentation interface and registry keys. Here's the report, if you want to know more about the malware, like indicators of compromise and other capabilities. 



 

The revelation comes after the new version of another information stealer called Atomic emerged a few months back. Atomic, which is also called AMOS, can gather data from Apple macOS systems. Information like credentials from Mozilla Firefox and Chromium-based browsers, crypto wallet information as well as other account passwords can be compromised.

"The new variant drops and uses a Python script to stay covert," Bitdefender researcher Andrei Lapusneanu said about Atomic. According to an IBM X-Force report, info stealer-related malware has increased by 266% in 2023 and the number is set to rise in 2024.

"These challenges are why organizations must enforce multi-factor authentication for all accounts, strengthen their IAM systems, and stress-test their environments," the report reads.

MORE ON MARKET REALIST
The Trump administration will have its hands full if this situation truly unfolds next year.
3 hours ago
With the Midterms next year, this crisis has become one of the key areas of conversation.
5 hours ago
Gyms are predicted to be popular in 2026 despite the advent of at-home fitness and virtual exercises, according to 86% of Americans surveyed.
5 hours ago
The host was not impressed with the question and said that it was shame that he knew the answers.
8 hours ago
He was overjoyed at first but that quickly turned into bitter disappointment.
9 hours ago
“Our AI-powered inventory management system is essential for supplying customers with what they need, when they need, and at the low costs," it stated.
10 hours ago
 “A program that provides roughly $50 an acre will not save the thousands of family farms that will go bankrupt before the end of the year," an expert stated.
12 hours ago
"This is another reason why I don’t like the Phrase category in the Bonus Round," a fan reacted.
16 hours ago
The host of the show was shocked upon hearing the answer and had to speak to the contestant's wife.
1 day ago
Reports suggest these three companies with strong ties to AI can make it to the coveted club.
1 day ago
Money manager Loius Navellier thinks the U.S. GDP could grow by 5% in 2026.
1 day ago
The contestant could have comfortably won the round but it was not meant to be.
1 day ago
The retailer's low price point may be a positive but product quality still matters.
1 day ago
The cost of raw beans, which account for at least 40% of production, has skyrocketed as a result of supply shortages.
1 day ago
The federal agencies have urged customers to keep it out of the reach of any kids.
1 day ago
The retailer has faced a lot of flak lately as people have been shocked and disappointed by its products.
1 day ago
On Christmas Eve, stores will have reduced hours, and on Christmas Day, all U.S. warehouses will remain shut.
1 day ago
Fans pointed that the puzzle was used twice during the early 2000s, and players had lost out on a car and the grand cash prize on both occasions. 
1 day ago
The airline said that it has made this policy change to be competitive in the market.
4 days ago
People do not usually think of Costco when planning a trip, but perhaps they should.
4 days ago