A new spam campaign distributing the TimbreStealer information stealer malware has been targeting users in Mexico since November 2023. The phishing emails contain financial themes and trick the user into downloading and executing malware from compromised websites. TimbreStealer exhibits sophisticated techniques like API hashing, Heaven’s Gate, and process hollowing to evade detection.

