PAPERMILL Campaign Abuses Signed Notepad++ and libcurl.dll Sideloading to Deploy VenomRAT 6.0.3 Against Indian Tax-Audit Targets
JUMPSEC is tracking PAPERMILL, a China-nexus, financially motivated phishing cluster that sends tax-audit lures (passing SPF, DKIM, and DMARC) with ISO disk images, sideloads a malicious libcurl.dll via a renamed Authenticode-signed Notepad++ binary, and uses…
JUMPSEC tracks PAPERMILL as an emerging, China-nexus, financially motivated cluster targeting Indian organizations with tax-audit themed emails that pass SPF, DKIM, and DMARC authentication. The emails deliver disk images (ISO per one report) that strip Mark-of-the-Web metadata, weakening SmartScreen warnings. The mounted image pairs a legitimately signed, renamed Notepad++ executable with a rogue libcurl.dll that is sideloaded, exporting four curl functions while executing loader logic in DllMain. A Donut shellcode loader then reflectively loads .NET VenomRAT 6.0.3 in memory with HVNC (hidden VNC), credential/data-stealing, and file-grabbing capability. Anti-analysis checks trigger a five-minute sleep on low memory, short uptime, or an unmoved cursor, and the loader repeatedly prompts for UAC elevation. Persistence is registry-based, with one report specifying a RunOnce key. VenomRAT was identified via its PBKDF2 salt and D/Invoke artifacts, and C2 traffic points to 154.36.188.201:4449. JUMPSEC assesses the tradecraft as Silver Fox-adjacent given Chinese infrastructure and Indian tax lures, but definitively Silver Fox operation is unconfirmed.
- Campaign tracked by JUMPSEC as PAPERMILL, an emerging China-nexus, financially motivated cluster (reported 2026-09-16)
- Targets in India receive tax-audit/tax-notice themed phishing emails that pass SPF, DKIM, and DMARC
- ISO disk images strip Mark-of-the-Web metadata, weakening SmartScreen/internet-origin warnings
- Renamed Authenticode-signed Notepad++ executable sideloads a malicious libcurl.dll exporting four curl functions, with loader logic in DllMain
- Donut shellcode loader reflectively loads .NET VenomRAT 6.0.3 in memory
- VenomRAT 6.0.3 has HVNC/hidden VNC plus credential/data-stealing and file-grabbing capability
- Anti-analysis delay of five minutes triggers on low memory, short uptime, or an unmoved cursor; loader repeatedly prompts for UAC elevation
- Persistence via registry (GBHackers reports Registry persistence; Cyber Security News specifies a RunOnce key)
Coverage timelineoldest first · each row is one article
- · 8h agoPAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers· 55
JUMPSEC tracks PAPERMILL, a China-nexus phishing campaign using a signed Notepad++ binary, libcurl.dll sideloading, and Donut loaders to deploy VenomRAT against Indian tax-audit targets.
- · 5h agoPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News· 55
PAPERMILL phishing campaign abuses a signed Notepad++ copy and tax-audit lures to deploy VenomRAT against targets in India.