A new infostealer spreading to organizations across Mexico heralds 2024's fresh season of tax-themed phishing attacks.
February 27, 2024 By Nate Nelson
Cybercriminals are spreading a new infostealer across Mexico by catching targets with tax season-related phishing lures — focusing on organizations rather than consumers.
The campaign observed by Cisco Talos goes back to November, when the first samples of "Timbre Stealer," a new unfocused but wide-ranging infostealer, first began spreading to targets via malicious emails. In the time since, it has spread to organizations across varied industries, most of all to manufacturing and transportation.
More recently, the threat actors have honed their phishing message using Mexico's tax season — the timing of which broadly overlaps with the US's — to catch their corporate targets off-guard and perpetuate the further spread of Timbre Stealer.