ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 2 sources: “PAPERMILL Campaign Abuses Signed Notepad++ and libcurl.dll Sideloading to Deploy VenomRAT 6.0.3 Against Indian Tax-Audit Targets” — merged summary and timeline →

PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks

mediumPhishing & fraud exploited in the wildimportance 55
AI summary · glm-5.3-flash

PAPERMILL phishing campaign abuses a signed Notepad++ copy and tax-audit lures to deploy VenomRAT against targets in India.

JUMPSEC tracks PAPERMILL as an emerging cluster whose emails pass SPF, DKIM, and DMARC and deliver tax-audit themed disk images. The mounted image pairs a legitimately signed, renamed executable with a rogue libcurl.dll for DLL sideloading, then uses a Donut shellcode loader to run VenomRAT 6.0.3 in memory with hidden VNC, data-stealing, and file-grabbing capabilities. The loader includes anti-analysis checks and RunOnce persistence, and lures plus China-connected infrastructure overlap with the Silver Fox ecosystem, though attribution remains unconfirmed.

  • Emails pass SPF/DKIM/DMARC and deliver tax-notice disk images that strip internet-origin warnings
  • Renamed signed Notepad++ launcher loads rogue libcurl.dll via DLL sideloading
  • Donut shellcode runs VenomRAT 6.0.3 in memory with VNC, data theft, and file grabbing
  • Anti-analysis checks trigger a five-minute delay on low memory, short uptime, or unmoved cursor
  • Tradecraft overlaps the Silver Fox ecosystem with Chinese infrastructure and Indian tax lures
VendorsNotepad++
Threat actorsPAPERMILL
MalwareVenomRAT
OrganizationsJUMPSEC
CountriesIndia

Indicators of compromiseAll →

TypeIndicatorContext
domain17dlz.cn.154.195 Sending infrastructure IP address Sending MTA mos1.17dlz[.]cn HELO/PTR value for the sending mail transfer agent Bulk-m
domainaidenllc.comRelated lure domain in July 2026 waves Sister delivery host aidenllc[.]com Related delivery host Sister delivery host gov-xnui[.]com
domaindgdskfds.uk.ccd38 Related sample: Tax_Notice_99674.img Sister lure domain dgdskfds[.]uk[.]cc Related lure domain in July 2026 waves Sister delivery
domaindownload.phpng location Payload / landing URL hxxps://dsfgssd[.]uk[.]cc/download[.]php Download endpoint for the payload Tracking-beacon path /a
domaindsfgssd.uk.cccn Mailer authentication host Payload / landing URL hxxps://dsfgssd[.]uk[.]cc/ Initial payload hosting location Payload / landing URL
domainekl1-neettr.bondaddress used by a sibling sample Related certificate domain ekl1-neettr[.]bond Domain linked to the sender IP 155.94.154.195 Note: IP ad
domaingisudyawz.inkxin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to 103.23.172.15 Sister lure title कर द
domaingov-xnui.comt aidenllc[.]com Related delivery host Sister delivery host gov-xnui[.]com Related delivery host Sister delivery host xjxfxn[.]com R
domainhsaui.ccIndicator Description Sender address / DKIM domain dfgfasd@hsaui[.]cc Observed sender address and DKIM domain Sending IP 155.94
domainjfbcea.comost xjxfxn[.]com Related delivery host Sister delivery host jfbcea[.]com Related delivery host DGA domain cluster tzawccsw[.]xin ,
domainpzisiauywa.xin.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to 103.23.172.15 Sist
domainsmtpman.cnthe sending mail transfer agent Bulk-mailer auth host smtp.smtpman[.]cn Mailer authentication host Payload / landing URL hxxps://
domaintzawccsw.xinhost jfbcea[.]com Related delivery host DGA domain cluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzi
domainxjxfxn.comt gov-xnui[.]com Related delivery host Sister delivery host xjxfxn[.]com Related delivery host Sister delivery host jfbcea[.]com R
domainzasudtytw.xiny host DGA domain cluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Dom
domainzixhasda.xincluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to
domainzxizusuy.xinm Related delivery host DGA domain cluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , g
ipv4103.119.15.189ax Penalty Notice, Government of India lure Secondary C2 IP 103.119.15.189 C2 address used by a sibling sample Related certificate dom
ipv4103.23.172.15n , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to 103.23.172.15 Sister lure title कर दंड सूचना – भारत सरकार Tax Penalty Not
ipv4154.36.188.201xe Process targeted by the payload on reconnect C2 endpoint 154.36.188.201:4449 VenomRAT command-and-control endpoint VenomRAT campaig
ipv4155.94.154.195aui[.]cc Observed sender address and DKIM domain Sending IP 155.94.154.195 Sending infrastructure IP address Sending MTA mos1.17dlz[.]
sha1009a05eaf082d20ae13a65abda12afd959cd76der Certificate metadata tied to the builder SHA-1 thumbprint 009a05eaf082d20ae13a65abda12afd959cd76de Pivot hash associated with the modified v6.0.3 builder SHA-
sha2560c0e4935f8df04e86056798d417bf3f485c640fa0322756c0a860af2a6bd0f1d252ca5e7b7c7fe237 Related sample: Tax_436454367.img SHA-256 0c0e4935f8df04e86056798d417bf3f485c640fa0322756c0a860af2a6bd0f1d Related 2023 Chinese-language sample SHA-256 38ec1f5e23f65b
sha256268a90d07cf02b16c091ef6cc52e3dbe17638bb722221807bc833c4c1299a8a9b679a73c2 Related sample: ClientAny.exe / skkr3.exe SHA-256 268a90d07cf02b16c091ef6cc52e3dbe17638bb722221807bc833c4c1299a8a9 Related sample: Tax_Notice_16695 (1).img SHA-256 f23708ae47
sha2562ff898c1a4bb0dd48687bbbc8cca646a896dc9ed24780a49523dfbf9fb94a4ece5a207315f7bf6ef74a966cbb5 libcurl.dll proxy loader SHA-256 2ff898c1a4bb0dd48687bbbc8cca646a896dc9ed24780a49523dfbf9fb94a4ec LIBCURL.DAT encrypted payload SHA-256 947221d0f1e2c9c090284
sha25638ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04c860af2a6bd0f1d Related 2023 Chinese-language sample SHA-256 38ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04c Related sample: Tax_Notice_23665.img SHA-256 a4098fe9ed421a
sha25672a321802d738e8bc6a0ab9d9d24b380be944fffbfc85094b889690b679a73c2321927fea66d Builder certificate SHA-256 thumbprint SHA-256 72a321802d738e8bc6a0ab9d9d24b380be944fffbfc85094b889690b679a73c2 Related sample: ClientAny.exe / skkr3.exe SHA-256 268a90d07
sha2568c1ba078598e09294d72293a42dcd878e183b6e5a207315f7bf6ef74a966cbb58eb192583f950c Tax_Notice_45594.exe signed launcher SHA-256 8c1ba078598e09294d72293a42dcd878e183b6e5a207315f7bf6ef74a966cbb5 libcurl.dll proxy loader SHA-256 2ff898c1a4bb0dd48687bbbc8c
sha256947221d0f1e2c9c09028491997406dd9f0cb5b65258556c86d201ec1ca538f5f80a49523dfbf9fb94a4ec LIBCURL.DAT encrypted payload SHA-256 947221d0f1e2c9c09028491997406dd9f0cb5b65258556c86d201ec1ca538f5f stage2.dll VenomRAT .NET DLL Install directory %APPDATA%\Mi
sha256a4098fe9ed421a6244c9fd4d3d1a632ff5f2ee4ffa204dff0587548932936d387e44e6a998e04c Related sample: Tax_Notice_23665.img SHA-256 a4098fe9ed421a6244c9fd4d3d1a632ff5f2ee4ffa204dff0587548932936d38 Related sample: Tax_Notice_99674.img Sister lure domain dgd
sha256d768222934f6014bf17c3d0a1ef4c35e02aa6fe1e89564e252ca5e7b7c7fe237e4b10e65d0b08e3 Related sample: ITDENF2026-4281.img SHA-256 d768222934f6014bf17c3d0a1ef4c35e02aa6fe1e89564e252ca5e7b7c7fe237 Related sample: Tax_436454367.img SHA-256 0c0e4935f8df04e86
sha256f23708ae470904490cb25d370185ca89c0d37e33fa5a3c652e4b10e65d0b08e34c1299a8a9 Related sample: Tax_Notice_16695 (1).img SHA-256 f23708ae470904490cb25d370185ca89c0d37e33fa5a3c652e4b10e65d0b08e3 Related sample: ITDENF2026-4281.img SHA-256 d768222934f6014
sha256f72bf7c1fd132262715820d839e4874c97d927b10072fb4709a1321927fea66dociated with the modified v6.0.3 builder SHA-256 thumbprint f72bf7c1fd132262715820d839e4874c97d927b10072fb4709a1321927fea66d Builder certificate SHA-256 thumbprint SHA-256 72a321802d73
sha256f945b3f2f29d62099683cbbf069ed5bc952d089c16a85fb314ac8fe0f0c10d2b{seq}} Unrendered variable in the From display name SHA-256 f945b3f2f29d62099683cbbf069ed5bc952d089c16a85fb314ac8fe0f0c10d2b Tax_Notice_45594.img ISO container SHA-256 fe0ddd8686324e0a
sha256fe0ddd8686324e0a8b07ed5ffdb4f56397c70b1b5a19d2916c8eb192583f950c14ac8fe0f0c10d2b Tax_Notice_45594.img ISO container SHA-256 fe0ddd8686324e0a8b07ed5ffdb4f56397c70b1b5a19d2916c8eb192583f950c Tax_Notice_45594.exe signed launcher SHA-256 8c1ba078598e09
urlhttps://dsfgssd[tpman[.]cn Mailer authentication host Payload / landing URL hxxps://dsfgssd[.]uk[.]cc/ Initial payload hosting location Payload / landin
Full article1,199 words · extracted from cybersecuritynews.com · click to collapse

A phishing campaign using a fake tax-audit notice is deploying VenomRAT through a signed copy of Notepad++. The operation, tracked as PAPERMILL, uses an email and a disk-image attachment to make a dangerous file look routine.

The attachment arrives with a tax-audit themed subject and can pass SPF, DKIM and DMARC checks. Opening it mounts what appears to be a local drive, allowing the malicious chain to start without warning labels carried by files downloaded from the internet.

Analysts at JUMPSEC identified the activity after reviewing a suspicious client email. They assessed PAPERMILL as an emerging cluster with tradecraft similar to the Silver Fox ecosystem, while stopping short of attributing it to that group.

JUMPSEC said in a report shared with Cyber Security News (CSN) that the campaign illustrates why a valid signature is not proof that an entire file set is safe.

It combines a familiar lure, a trusted application, a booby-trapped supporting file and an encrypted final payload, helping attackers slip past basic security controls. This approach complicates incident investigation and response for defenders.

PAPERMILL Hackers Abuse Signed Notepad++

The email directs recipients to a tax-notice-themed disk image. Once mounted, the container presents a renamed, legitimately signed application, a counterfeit library and an encrypted data file.

This technique can strip the internet-origin mark from the files inside, reducing the warnings Windows would normally display. The signed executable has not been altered. Instead, it is renamed and made to load the nearby malicious library.

This form of DLL sideloading lets harmful code run beside a trusted process, a pattern also seen in recent DLL sideloading campaigns.

The rogue DLL exposes only the functions the legitimate program expects, allowing the application to open normally while the loader works in the background.

Attack chain (Source - JumpSEC)
Attack chain (Source – JumpSEC)

It also uses misleading section names intended to confuse analysis tools, then decrypts its data file and launches the next stage from memory.

The loader checks whether the device resembles an automated analysis environment. Low memory, little free storage, a short uptime, an unmoved cursor or a low display resolution can trigger a five-minute delay rather than an immediate exit.

VenomRAT delivery and defensive steps

After the delay and privilege checks, the loader can seek administrator approval, create a RunOnce persistence entry and copy components into user-profile folders.

It then uses a Donut shellcode loader to run a .NET payload in memory. That layered design mirrors the disk-image VenomRAT delivery technique, but PAPERMILL adds a signed-program sideloading stage.

The recovered configuration identifies VenomRAT version 6.0.3 with hidden virtual network computing, data-stealing and file-grabbing capabilities.

Its server is configured for remote command traffic, creating a risk of account theft, surveillance and follow-on intrusion if a victim launches the attachment. Related samples and infrastructure suggest a campaign focused on Indian tax-themed targets.

Researchers found links to the broader Silver Fox-style playbook, including China-connected infrastructure and tax lures, but noted key differences in the chosen host program, loader and remote-access tool.

That caution matters: a shared technique can point to an ecosystem or copycat activity, rather than prove that one named actor ran the campaign.

Organizations should treat unsolicited tax notices and unexpected disk-image files as high risk, even when an email passes authentication checks.

Staff should independently verify tax-related requests through known channels, while security teams should block or closely inspect IMG and ISO files delivered by email and investigate unusual mounted drives.

Defenders should also alert on signed applications loading unexpected DLLs from user-writable folders, unfamiliar RunOnce entries and suspicious network connections from trusted or system-lookalike processes.

These controls complement lessons from SilverFox trusted software abuse and can expose the behavior that per-download file hashes may miss.

Because PAPERMILL can generate fresh containers, hashes alone are unlikely to provide durable coverage. Hunting for loader file relationships, library naming patterns, persistence locations and command traffic gives responders stronger ways to find infections and contain them before attackers expand access.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Sender address / DKIM domaindfgfasd@hsaui[.]ccObserved sender address and DKIM domain
Sending IP155.94.154.195Sending infrastructure IP address
Sending MTAmos1.17dlz[.]cnHELO/PTR value for the sending mail transfer agent
Bulk-mailer auth hostsmtp.smtpman[.]cnMailer authentication host
Payload / landing URLhxxps://dsfgssd[.]uk[.]cc/Initial payload hosting location
Payload / landing URLhxxps://dsfgssd[.]uk[.]cc/download[.]phpDownload endpoint for the payload
Tracking-beacon path/api/mailer/open?task=<GUID>&t=<token>Beacon path, with host left as localhost:6688
Lure subjectकर लेखापरीक्षा परिणाम No. ITD/SCNU/2026-<seq>Tax-audit themed phishing subject
Mailer tell{{seq}}Unrendered variable in the From display name
SHA-256f945b3f2f29d62099683cbbf069ed5bc952d089c16a85fb314ac8fe0f0c10d2bTax_Notice_45594.img ISO container
SHA-256fe0ddd8686324e0a8b07ed5ffdb4f56397c70b1b5a19d2916c8eb192583f950cTax_Notice_45594.exe signed launcher
SHA-2568c1ba078598e09294d72293a42dcd878e183b6e5a207315f7bf6ef74a966cbb5libcurl.dll proxy loader
SHA-2562ff898c1a4bb0dd48687bbbc8cca646a896dc9ed24780a49523dfbf9fb94a4ecLIBCURL.DAT encrypted payload
SHA-256947221d0f1e2c9c09028491997406dd9f0cb5b65258556c86d201ec1ca538f5fstage2.dll VenomRAT .NET DLL
Install directory%APPDATA%\Microsoft\Crypto\RuntimeBroker\Loader installation directory
VenomRAT runtime directory%APPDATA%\MyData\Runtime folder used by the RAT
Dropped filesRuntimeBroker.exe, libcurl.dll, libcurl.datLoader-stage files placed on disk
Staging temporary names*_dbg_src.tmp, *_dbg_dst.tmpTemporary staging file patterns
Persistence keyHKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce → …\RuntimeBroker\RuntimeBroker.exeRegistry RunOnce persistence
MasqueradeRuntimeBroker.exeImpersonates Windows Runtime Broker
Internal DLL namelibcurl.dll_38768.dllHunt pattern: libcurl.dll_<digits>.dll
Loader module base0x00000002FFF20000Fixed memory mapping inside the affected process
Loader section names.nvdata ×3, .nvtext, .pdataMisleading PE section names, with no exception directory
VenomRAT mutexxkoqvgcojtqgiMutex used by the VenomRAT payload
VenomRAT HVNC workercvtres.exeProcess targeted by the payload on reconnect
C2 endpoint154.36.188.201:4449VenomRAT command-and-control endpoint
VenomRAT campaign groupDefaultGroup value in the recovered configuration
VenomRAT master keycFlrTU1YN25QN2lkc05ZWDJVWkY0R1FtUUcyNmgyY1Y=Base64 key that decodes to pYkMMX7nP7idsNYX2UZF4GQmQG26h2cV
PBKDF2 saltVenomRATByVenomConfiguration-decryption salt
Version bannerVenom RAT + HVNC + Stealer + Grabber v6.0.3Version string, including two spaces before v6.0.3
Server X.509 subject / issuerCN=VenomRAT / C=CN, L=SH, O=VenomRAT By qwqdanchun, OU=qwqdanchun, CN=LMTEAM ServerCertificate metadata tied to the builder
SHA-1 thumbprint009a05eaf082d20ae13a65abda12afd959cd76dePivot hash associated with the modified v6.0.3 builder
SHA-256 thumbprintf72bf7c1fd132262715820d839e4874c97d927b10072fb4709a1321927fea66dBuilder certificate SHA-256 thumbprint
SHA-25672a321802d738e8bc6a0ab9d9d24b380be944fffbfc85094b889690b679a73c2Related sample: ClientAny.exe / skkr3.exe
SHA-256268a90d07cf02b16c091ef6cc52e3dbe17638bb722221807bc833c4c1299a8a9Related sample: Tax_Notice_16695 (1).img
SHA-256f23708ae470904490cb25d370185ca89c0d37e33fa5a3c652e4b10e65d0b08e3Related sample: ITDENF2026-4281.img
SHA-256d768222934f6014bf17c3d0a1ef4c35e02aa6fe1e89564e252ca5e7b7c7fe237Related sample: Tax_436454367.img
SHA-2560c0e4935f8df04e86056798d417bf3f485c640fa0322756c0a860af2a6bd0f1dRelated 2023 Chinese-language sample
SHA-25638ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04cRelated sample: Tax_Notice_23665.img
SHA-256a4098fe9ed421a6244c9fd4d3d1a632ff5f2ee4ffa204dff0587548932936d38Related sample: Tax_Notice_99674.img
Sister lure domaindgdskfds[.]uk[.]ccRelated lure domain in July 2026 waves
Sister delivery hostaidenllc[.]comRelated delivery host
Sister delivery hostgov-xnui[.]comRelated delivery host
Sister delivery hostxjxfxn[.]comRelated delivery host
Sister delivery hostjfbcea[.]comRelated delivery host
DGA domain clustertzawccsw[.]xin, zxizusuy[.]xin, zasudtytw[.]xin, zixhasda[.]xin, pzisiauywa[.]xin, gisudyawz[.]inkDomains resolving to 103.23.172.15
Sister lure titleकर दंड सूचना – भारत सरकारTax Penalty Notice, Government of India lure
Secondary C2 IP103.119.15.189C2 address used by a sibling sample
Related certificate domainekl1-neettr[.]bondDomain linked to the sender IP 155.94.154.195

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/papermill-hackers/