{"id":2616,"date":"2024-02-27T20:08:05","date_gmt":"2024-02-27T20:08:05","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/mexico-timbre-stealer-campaign-heralds-2024-tax-season-threat"},"modified":"2024-02-27T20:08:05","modified_gmt":"2024-02-27T20:08:05","slug":"mexicos-timbre-stealer-campaign-targets-manufacturing","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/02\/27\/mexicos-timbre-stealer-campaign-targets-manufacturing\/","title":{"rendered":"Mexico&#8217;s &#8216;Timbre Stealer&#8217; Campaign Targets Manufacturing"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt0ed7895701e2feda\/65de43c1136b90040a17cc3c\/pesos-Tom_King-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cybercriminals are spreading a new infostealer across Mexico by catching targets with tax season-related phishing lures \u2014 focusing on organizations rather than consumers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/blog.talosintelligence.com\/timbrestealer-campaign-targets-mexican-users\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">The campaign observed by Cisco Talos<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> goes back to November, when the first samples of &#8220;Timbre Stealer,&#8221; a new unfocused but wide-ranging infostealer, first began spreading to targets via malicious emails. In the time since, it has spread to organizations across varied industries, most of all to manufacturing and transportation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">More recently, the threat actors have honed their phishing message using Mexico&#8217;s tax season \u2014 the timing of which broadly overlaps with the US&#8217;s \u2014 to catch their corporate targets off-guard and perpetuate the further spread of Timbre Stealer.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Breakdown of Timbre Stealer\">A Breakdown of Timbre Stealer<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Upon execution, Timbre Stealer first determines if its newly infected machine is of interest. Specifically, it checks that the system language is not Russian (perhaps a hint at the threat actor behind this campaign) and that its time zone is aligned with Latin America.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Next, it double-checks that the system hasn&#8217;t been previously infected and that it&#8217;s not running in a sandbox environment. Other stealth mechanisms include its use of custom loaders, direct system calls that bypass standard API monitoring, and restricting access to its infrastructure only to users in a specific geographic region.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We commonly see actors implement anti-analysis techniques; this is that on steroids,&#8221; says Guilherme Venere, threat researcher for Cisco Talos. &#8220;The authors behind this threat do not just implement anti-analysis; they implement as many anti-analysis capabilities as they can, which increases the difficulty on the researcher to take it apart as well as for technology to detect it.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once firmly planted, Timbre Stealer propagates through the victim, beginning its job collecting a vast spread of diverse data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It uses the Windows Management Instrumentation (WMI) interface and registry keys to collect information from the operating system. It also scans a number of fundamental directories, like the Desktop, Documents, and Downloads folders, for purposes that aren&#8217;t entirely clear.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Certain strings in its code suggest that it scans files and directories for information relating to apps such as Microsoft Office and OneDrive, Windows Media Player, various browsers (Firefox, Microsoft Edge, Internet Explorer, and Chrome), Dropbox, Avast, AMD, Brother, HP, Intel, and more.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s also interested in certain URLs relating to popular websites \u2014 Google.com, Wikipedia.org, Facebook.com, and the like \u2014 which Talos researchers speculated may have to do with network sniffing capabilities.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Beware Tax-Season Scams\">Beware Tax-Season Scams<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like holiday-season shopping, tax deadlines reliably provide fertile ground for financially motivated cyberattackers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As Venere explains, &#8220;Every year we see actors taking advantage of current affairs, and tax season is one of the biggest. It unfortunately checks a lot of boxes for criminals as it involves large sums of money, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/remcos-rat-tax-pros-worksers-filing-info\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">valuable personally identifiable information (PII)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and is something that every adult has to deal with. When you combine them, it is a perfect storm for criminals looking to make money.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Taxes are also complicated, boring, and stressful \u2014 factors that might make victims less discerning about what they click on.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In this latest campaign, for example, besides generic invoices, the attackers designed a lure around &#8220;Comprobante Fiscal Digital por Internet&#8221; (CDFI) (in English: online fiscal digital invoice), Mexico&#8217;s mandatory electronic invoice standard used for tax reporting. When disinterested and unwitting targets follow the malicious link, they&#8217;re led to download Timbre Stealer.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Besides a general defense-in-depth approach to cybersecurity, Venere recommends that around this time of year &#8220;organizations should be giving <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/7-tips-to-secure-the-enterprise-against-tax-scams\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">user training about the prevalence of tax-based spam<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, with a focus on those areas most likely to be impacted, like finance.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/mexico-timbre-stealer-campaign-heralds-2024-tax-season-threat\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals are spreading a new infostealer across Mexico by catching<\/p>\n","protected":false},"author":12,"featured_media":2617,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2616","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?fit=2560%2C1707&ssl=1",2560,1707,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?fit=2048%2C1366&ssl=1",2048,1366,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/mexicos-timbre-stealer-campaign-targets-manufacturing-scaled.jpg?fit=2560%2C1707&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2616","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2616"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2616\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2617"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}