The emerging PAPERMILL cluster is targeting Indian organizations with tax-audit-themed phishing emails carrying an ISO 9660 disk-image attachment disguised as an .img file. Mounting the image helps evade Mark-of-the-Web protections; victims are then induced to launch a renamed, legitimately signed Notepad++ executable posing as a tax notice. That executable DLL-sideloads a malicious libcurl.dll proxy, which decrypts and executes a multistage payload.
The loader employs anti-analysis delays and sandbox checks, may request UAC elevation and create RunOnce persistence, and uses Donut reflective loading to launch VenomRAT 6.0.3 in memory. The configured command-and-control server is 154.36.188.201:4449; VenomRAT enables hidden VNC, data theft, file collection, remote command execution, and follow-on intrusion. Researchers assess the financially motivated activity as likely China-nexus and Silver Fox-adjacent based on its lures, delivery methods, and infrastructure, but have not attributed it conclusively to Silver Fox.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Multiple sibling disk-image samples, including Tax_Notice_16695.img, ITDENF2026-4281.img, and Tax_436454367.img, were associated with the same VenomRAT builder certificate later linked to PAPERMILL. Additional samples Tax_Notice_23665.img and Tax_Notice_99674.img reportedly contacted the same command-and-control infrastructure.
JUMPSEC documented that the Tax_Notice_45594.img chain used a malicious libcurl.dll loader that attempted UAC elevation, established RunOnce persistence via a masqueraded RuntimeBroker.exe, and delayed execution under sandbox-like conditions. The researchers also disclosed the phishing URL, sender and mail-host infrastructure, and hashes for the ISO, loader, encrypted stage, and VenomRAT payload.
JUMPSEC assessed the activity with high confidence as China-nexus, financially motivated commodity crimeware targeting Indian entities. The researchers found moderate-to-high-confidence similarities to Silver Fox tradecraft but stated that the available evidence did not support confident attribution to Silver Fox.
The PAPERMILL cluster conducted phishing attacks using Indian tax-audit notices and an ISO 9660 disk image masquerading as an IMG attachment. The image used a renamed, legitimately signed Notepad++ executable to sideload a malicious libcurl.dll loader, which decrypted and launched VenomRAT v6.0.3; the analyzed payload was configured to use 154.36.188.201:4449 for command and control.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 47 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcejumpsec.com
Open sourcejumpsec.com
Open sourcejumpsec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.