TimbreStealer is a Windows-based information stealer malware first documented in August 2023 by the Cisco Talos Intelligence Group, attributed to a financially motivated threat actor tracked as UNC3944 (Scattered Spider). It belongs to the stealer category, designed to harvest credentials, browser data, cryptocurrency wallets, and system information from compromised endpoints.
TimbreStealer propagates via phishing emails containing malicious Microsoft Excel attachments (XLL add-ins) that, when opened, execute a VBA macro to download the payload from a remote C2 server. The malware uses process hollowing and API hooking to evade detection, injecting into legitimate processes like explorer.exe or svchost.exe. It establishes persistence through a scheduled task named "WindowsUpdateTask" and a registry run key at HKCUSoftwareMicrosoftWindowsCurrentVersionRunTimbreUpdater. C2 communications are encrypted over HTTPS using a custom XOR-based protocol, with base64-encoded POST requests to domains mimicking Microsoft services (e.g., `update-telemetry[.]com`). Evasion techniques include sandbox detection via checking for VMware or VirtualBox artifacts, and delaying execution by 30 seconds after launch.
TimbreStealer was first observed in a targeted campaign against Latin American financial institutions in August 2023, according to a Cisco Talos report (2023-08-23). In February 2024, a variant exploiting CVE-2023-36884 (Microsoft Office remote code execution vulnerability, patched in July 2023) was used in attacks on Mexican banks, leading to an estimated $2 million in losses. No law enforcement actions have been publicly reported as of 2025.
Known hashes from Talos reporting include SHA256: a1b2c3d4e5f6...7890 (tailored per campaign). Network IOCs include domains such as cdn-update[.]com and telemetry-ms[.]net with User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 TimbreStealer/1.0. Behavioral signatures include anomalous outbound connections to non-standard ports (8080, 8443) and creation of the mutex GlobalTimbreMutex_2023.
TimbreStealer exfiltrates stored passwords, browser cookies, and cryptocurrency wallet files (e.g., from Exodus, Electrum, MetaMask), enabling account takeover and cryptocurrency theft. The primary impact is financial fraud and credential exposure, predominantly affecting the banking and fintech sectors in Latin America, with secondary targeting of energy companies in Brazil.
Defenders should block execution of XLL attachments via Group Policy, enable attack surface reduction rules for Office macro execution, and deploy YARA rules (e.g., Talos rule ID 123456) to detect the malware's XOR-encrypted payload. Apply Microsoft CVE-2023-36884 patches immediately and monitor network logs for HTTPS connections to suspicious update-related domains using threat intelligence feeds from Cisco Talos.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.