Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time
Malwarebytes (TL-2026-2289) is a low-severity tracked intrusion set, first published 2026-09-02. It has no confirmed attribution, maps to 11 MITRE ATT&CK techniques (T1204.001, T1566.002, T1566.004), and is covered by 9 detection rules and 12 indicators of compromise.
Key facts for TL-2026-2289
- Threat ID
- TL-2026-2289
- Severity
- LOW
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-09-02
- Last reviewed
- 2026-09-02
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- consumer, gaming, financial services, government services, technology
- Target regions
- united states of america, Global
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Malwarebytes
Malware and tooling: Donald Trump
Malwarebytes threat-research telemetry (April 15-July 14, 2026) shows scam operators deliberately match scam type to delivery channel and timing: toll-fee scams arrive almost entirely by email/SMS, romance scams surface first on social media, IRS scams are mostly delivered by phone, and job scams arrive via email, with scam-text volume peaking at 12:00pm ET on Fridays.
How Malwarebytes works
Malwarebytes' Scam Guard threat-research systems analyzed anonymized global scam telemetry collected April 15 through July 14, 2026, and found that scam operators consistently pair a scam narrative with the delivery channel most likely to make it credible rather than spraying a single lure across every channel. Toll-fee scams (fake unpaid-toll notices threatening late fees or license suspension) arrive by email or SMS in roughly nine out of ten cases; romance scams surface first on social media roughly six times out of ten; IRS/tax-impersonation scams are delivered by phone call about half the time; job/employment scams arrive through ordinary work channels (email); and giveaway scams are more likely to appear in social-media feeds than in email or text. Malwarebytes also blocks approximately 500,000 phishing websites per day, and its Scam Guard tool flags roughly one in five analyzed sessions as high-risk.
The report identifies a sharp temporal pattern in SMS-based scam delivery: the busiest hour for scam texts on the US East Coast is 12:00pm ET, which is 874% busier than the quietest hour (1:00am ET), and scam-text volume climbs steadily across the week to peak on Fridays, roughly 50% higher than the Sunday low. This channel-and-timing discipline mirrors patterns independently documented elsewhere: the FBI IC3 issued a nationwide alert in April 2024 (PSA240412) describing an ongoing unpaid-toll smishing campaign that directs victims to lookalike toll-payment domains (e.g., myturnpiketollservices[.]com-style URLs) to harvest payment and personal information, and the IRS's 2026 'Dirty Dozen' scam list (IR-2026-30, March 2026) separately warns that IRS-impersonation phone scams increasingly use AI-generated voice synthesis and spoofed caller ID to sound authoritative.
On impersonation, the report finds MrBeast is the most-impersonated public figure, used in roughly 30% of impersonation-based scams-well ahead of Elon Musk and Donald Trump, who round out the top three-typically via crypto-giveaway lures and 'transfer fee' swindles that demand an upfront payment to 'unlock' a prize that never materializes. This matches independently reported MrBeast-impersonation campaigns that use AI deepfake video and compromised Discord accounts (Bitdefender documented a stolen-Discord-account MrBeast giveaway wave on July 3, 2026) to push victims toward fake investment/gambling sites. Among brands, Google, Microsoft, Apple, Roblox, and Amazon are the five most-impersonated names, with Google's brand abused at least twice as often as Amazon's.
The report also flags a mid-June to mid-July 2026 spike in gaming-platform scam activity, with Roblox scam activity up 15% and Steam scam activity up 19% over that window, and about half of all gaming-related scams causing a financial hit of $1,000 or more to the victim. This aligns with independent 2026 reporting: Bitdefender warned on March 30, 2026 of a fake game-playtest-invitation campaign spreading malware and stealing Steam/Discord credentials via spoofed developer accounts and lookalike login pages, and Guardio's Q1 2025 phishing-brand report already ranked Steam as the #1 and Roblox as the #4 most-imitated brand in phishing overall, indicating the mid-2026 spike sits on top of an already-elevated baseline for these platforms.
This is a threat-research trend/awareness report from Malwarebytes' own proprietary telemetry rather than a specific exploited vulnerability, malware family, or attributed campaign; there is no CVE, PoC, or nation-state TTP associated with it. Its value is defensive: it lets SOC/fraud teams and consumer-protection programs tune channel-specific detection and user-education messaging (e.g., treat unsolicited toll/IRS/brand-alert messages as high-risk regardless of surface plausibility, and expect scam-text volume to spike around midday Friday ET).
MITRE ATT&CK techniques used in TL-2026-2289
Execution
Initial Access
T1566.002 Spearphishing Link; T1566.004 Spearphishing Voice; T1660 Phishing
Resource Development
T1583.001 Domains; T1585.001 Social Media Accounts; T1585.002 Email Accounts
Reconnaissance
T1598.003 Spearphishing Link; T1598.004 Spearphishing Voice
Impact
Stealth
Remediation for Malwarebytes
Immediate actions
- Do not click links or call phone numbers in unsolicited emails, texts, or social-media DMs claiming to be from a toll service, the IRS, or a well-known brand/public figure
- Verify toll, tax, and account-alert claims only by navigating to the organization's official site or calling a phone number obtained independently, never one embedded in the inbound message
- Never provide PINs, passwords, one-time verification codes, or send payment/cryptocurrency during an unsolicited call, text, or DM, even if caller ID or the sender profile appears legitimate
- Treat any request for a 'transfer fee,' 'verification deposit,' or 'unlock payment' to release a prize or giveaway as a guaranteed scam
Workarounds
- Independently look up and call back organizations using numbers from official statements or the organization's verified website, rather than numbers supplied in the inbound message
- Enable platform-native scam/spam-message filtering where available (carrier SMS filtering, email provider phishing filters, Discord DM privacy settings restricting messages from non-friends)
Longer-term hardening
- Deploy SMS/mobile threat filtering (e.g., Malwarebytes Mobile Security or equivalent) to intercept scam texts before delivery, especially around the documented midday-Friday-ET peak
- Deploy browser-level phishing/URL-reputation blocking (e.g., Malwarebytes Browser Guard or equivalent) for consumer and BYOD endpoints
- Build channel-specific user-education programs: toll/job scams arrive by email-SMS, romance/giveaway scams surface first on social media, IRS/tech-support scams arrive by phone
- For organizations with gaming-platform-adjacent users (Roblox/Steam/Discord/Minecraft), specifically warn against unsolicited playtest invitations, developer 'testing' offers, and login prompts reached via Discord or DM links
Timeline of Malwarebytes
- FBI IC3 issues nationwide PSA240412 warning of an ongoing unpaid-toll smishing campaign, establishing the toll-scam channel/domain pattern later confirmed by Malwarebytes telemetry.
- IRS publishes its 2026 'Dirty Dozen' scam list (IR-2026-30), warning that IRS-impersonation phone scams increasingly use AI-generated voice synthesis and spoofed caller ID.
- Bitdefender warns of a fake game-playtest-invitation campaign spreading malware and stealing Steam/Discord accounts, preceding the gaming-platform scam spike Malwarebytes later measures.
- Malwarebytes begins the telemetry collection window analyzed in the report.
- Approximate start of the mid-June gaming-platform scam-activity spike (Roblox +15%, Steam +19%) observed in Malwarebytes telemetry.
- Bitdefender documents a MrBeast-impersonation giveaway scam spread via stolen/compromised Discord accounts.
- Malwarebytes telemetry collection window closes; mid-July marks the approximate end of the gaming-platform scam-activity spike.
- Malwarebytes publishes 'Scammers are getting smarter about where they target you,' disclosing the channel-matching, timing, and impersonation findings documented in this record.
Sources cited for Malwarebytes
- Scammers are getting smarter about where they target you
- Nationwide Public Safety Alert Regarding Text Scam Claiming Unpaid Tolls (PSA240412)
- Dirty Dozen tax scams for 2026: IRS reminds taxpayers to watch out for dangerous threats (IR-2026-30)
- Steam Tops Q1 2025 Most Imitated Brands List
- Hackers are using stolen Discord accounts to spread fake MrBeast giveaways
- The Fake Game Playtest Scam Explained
More in threat intel
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C Domains Surge +771%
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)
Detection coverage for TL-2026-2289
As of 2026-09-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2289 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.