Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time

Malwarebytes (TL-2026-2289) is a low-severity tracked intrusion set, first published 2026-09-02. It has no confirmed attribution, maps to 11 MITRE ATT&CK techniques (T1204.001, T1566.002, T1566.004), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2289

Threat ID
TL-2026-2289
Severity
LOW
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-09-02
Last reviewed
2026-09-02
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
consumer, gaming, financial services, government services, technology
Target regions
united states of america, Global
Detection rules
9
Indicators of compromise
12

Malware and tooling in Malwarebytes

Malware and tooling: Donald Trump

Malwarebytes threat-research telemetry (April 15-July 14, 2026) shows scam operators deliberately match scam type to delivery channel and timing: toll-fee scams arrive almost entirely by email/SMS, romance scams surface first on social media, IRS scams are mostly delivered by phone, and job scams arrive via email, with scam-text volume peaking at 12:00pm ET on Fridays.

How Malwarebytes works

Malwarebytes' Scam Guard threat-research systems analyzed anonymized global scam telemetry collected April 15 through July 14, 2026, and found that scam operators consistently pair a scam narrative with the delivery channel most likely to make it credible rather than spraying a single lure across every channel. Toll-fee scams (fake unpaid-toll notices threatening late fees or license suspension) arrive by email or SMS in roughly nine out of ten cases; romance scams surface first on social media roughly six times out of ten; IRS/tax-impersonation scams are delivered by phone call about half the time; job/employment scams arrive through ordinary work channels (email); and giveaway scams are more likely to appear in social-media feeds than in email or text. Malwarebytes also blocks approximately 500,000 phishing websites per day, and its Scam Guard tool flags roughly one in five analyzed sessions as high-risk.

The report identifies a sharp temporal pattern in SMS-based scam delivery: the busiest hour for scam texts on the US East Coast is 12:00pm ET, which is 874% busier than the quietest hour (1:00am ET), and scam-text volume climbs steadily across the week to peak on Fridays, roughly 50% higher than the Sunday low. This channel-and-timing discipline mirrors patterns independently documented elsewhere: the FBI IC3 issued a nationwide alert in April 2024 (PSA240412) describing an ongoing unpaid-toll smishing campaign that directs victims to lookalike toll-payment domains (e.g., myturnpiketollservices[.]com-style URLs) to harvest payment and personal information, and the IRS's 2026 'Dirty Dozen' scam list (IR-2026-30, March 2026) separately warns that IRS-impersonation phone scams increasingly use AI-generated voice synthesis and spoofed caller ID to sound authoritative.

On impersonation, the report finds MrBeast is the most-impersonated public figure, used in roughly 30% of impersonation-based scams-well ahead of Elon Musk and Donald Trump, who round out the top three-typically via crypto-giveaway lures and 'transfer fee' swindles that demand an upfront payment to 'unlock' a prize that never materializes. This matches independently reported MrBeast-impersonation campaigns that use AI deepfake video and compromised Discord accounts (Bitdefender documented a stolen-Discord-account MrBeast giveaway wave on July 3, 2026) to push victims toward fake investment/gambling sites. Among brands, Google, Microsoft, Apple, Roblox, and Amazon are the five most-impersonated names, with Google's brand abused at least twice as often as Amazon's.

The report also flags a mid-June to mid-July 2026 spike in gaming-platform scam activity, with Roblox scam activity up 15% and Steam scam activity up 19% over that window, and about half of all gaming-related scams causing a financial hit of $1,000 or more to the victim. This aligns with independent 2026 reporting: Bitdefender warned on March 30, 2026 of a fake game-playtest-invitation campaign spreading malware and stealing Steam/Discord credentials via spoofed developer accounts and lookalike login pages, and Guardio's Q1 2025 phishing-brand report already ranked Steam as the #1 and Roblox as the #4 most-imitated brand in phishing overall, indicating the mid-2026 spike sits on top of an already-elevated baseline for these platforms.

This is a threat-research trend/awareness report from Malwarebytes' own proprietary telemetry rather than a specific exploited vulnerability, malware family, or attributed campaign; there is no CVE, PoC, or nation-state TTP associated with it. Its value is defensive: it lets SOC/fraud teams and consumer-protection programs tune channel-specific detection and user-education messaging (e.g., treat unsolicited toll/IRS/brand-alert messages as high-risk regardless of surface plausibility, and expect scam-text volume to spike around midday Friday ET).

MITRE ATT&CK techniques used in TL-2026-2289

Execution

T1204.001 Malicious Link

Initial Access

T1566.002 Spearphishing Link; T1566.004 Spearphishing Voice; T1660 Phishing

Resource Development

T1583.001 Domains; T1585.001 Social Media Accounts; T1585.002 Email Accounts

Reconnaissance

T1598.003 Spearphishing Link; T1598.004 Spearphishing Voice

Impact

T1657 Financial Theft

Stealth

T1684.001 Impersonation

Remediation for Malwarebytes

Immediate actions

  • Do not click links or call phone numbers in unsolicited emails, texts, or social-media DMs claiming to be from a toll service, the IRS, or a well-known brand/public figure
  • Verify toll, tax, and account-alert claims only by navigating to the organization's official site or calling a phone number obtained independently, never one embedded in the inbound message
  • Never provide PINs, passwords, one-time verification codes, or send payment/cryptocurrency during an unsolicited call, text, or DM, even if caller ID or the sender profile appears legitimate
  • Treat any request for a 'transfer fee,' 'verification deposit,' or 'unlock payment' to release a prize or giveaway as a guaranteed scam

Workarounds

  • Independently look up and call back organizations using numbers from official statements or the organization's verified website, rather than numbers supplied in the inbound message
  • Enable platform-native scam/spam-message filtering where available (carrier SMS filtering, email provider phishing filters, Discord DM privacy settings restricting messages from non-friends)

Longer-term hardening

  • Deploy SMS/mobile threat filtering (e.g., Malwarebytes Mobile Security or equivalent) to intercept scam texts before delivery, especially around the documented midday-Friday-ET peak
  • Deploy browser-level phishing/URL-reputation blocking (e.g., Malwarebytes Browser Guard or equivalent) for consumer and BYOD endpoints
  • Build channel-specific user-education programs: toll/job scams arrive by email-SMS, romance/giveaway scams surface first on social media, IRS/tech-support scams arrive by phone
  • For organizations with gaming-platform-adjacent users (Roblox/Steam/Discord/Minecraft), specifically warn against unsolicited playtest invitations, developer 'testing' offers, and login prompts reached via Discord or DM links

Timeline of Malwarebytes

  • FBI IC3 issues nationwide PSA240412 warning of an ongoing unpaid-toll smishing campaign, establishing the toll-scam channel/domain pattern later confirmed by Malwarebytes telemetry.
  • IRS publishes its 2026 'Dirty Dozen' scam list (IR-2026-30), warning that IRS-impersonation phone scams increasingly use AI-generated voice synthesis and spoofed caller ID.
  • Bitdefender warns of a fake game-playtest-invitation campaign spreading malware and stealing Steam/Discord accounts, preceding the gaming-platform scam spike Malwarebytes later measures.
  • Malwarebytes begins the telemetry collection window analyzed in the report.
  • Approximate start of the mid-June gaming-platform scam-activity spike (Roblox +15%, Steam +19%) observed in Malwarebytes telemetry.
  • Bitdefender documents a MrBeast-impersonation giveaway scam spread via stolen/compromised Discord accounts.
  • Malwarebytes telemetry collection window closes; mid-July marks the approximate end of the gaming-platform scam-activity spike.
  • Malwarebytes publishes 'Scammers are getting smarter about where they target you,' disclosing the channel-matching, timing, and impersonation findings documented in this record.

Sources cited for Malwarebytes

More in threat intel

Detection coverage for TL-2026-2289

As of 2026-09-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2289 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats