PAPERMILL is an emerging, financially motivated, China-nexus cybercrime activity cluster targeting Indian entities with tax-audit-themed phishing campaigns. The designation is provisional and identifies a distinct activity cluster rather than an established threat group. Its tradecraft resembles the Silver Fox ecosystem, but PAPERMILL has not been conclusively attributed to Silver Fox or established as one of its subgroups. The infection chain uses phishing emails carrying disk-image attachments containing a renamed, unmodified, legitimately signed Notepad++ executable, a malicious proxy DLL, and an encrypted payload. The disk-image packaging allows contained files to avoid inheriting Mark-of-the-Web metadata, reducing downloaded-file warnings. The signed executable sideloads the malicious DLL while retaining apparently normal application behavior. The loader decrypts a multistage payload and uses Donut shellcode to reflectively load a .NET VenomRAT payload in memory. The loader employs misleading executable-section metadata and checks system resources, uptime, display characteristics, and user activity for signs of automated analysis. Suspicious conditions trigger a five-minute execution delay. It also attempts privilege elevation through repeated UAC prompts, establishes RunOnce persistence, and masquerades as a legitimate Windows component. The deployed VenomRAT version 6.0.3 provides hidden virtual network computing, data stealing, file grabbing, and remote command execution, enabling remote control, exfiltration, and follow-on intrusion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
38 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An emerging phishing activity cluster targeting Indian tax-themed recipients. It delivers VenomRAT through tax-audit lures and disk-image attachments, abusing a renamed legitimately signed Notepad++ executable for DLL sideloading.
An emerging activity cluster delivering VenomRAT through Indian tax-audit-themed phishing and disk-image attachments. Its infection chain abuses a renamed, legitimately signed Notepad++ executable to sideload a malicious DLL, decrypt an embedded payload and execute it in memory. The delivered RAT supports hidden remote desktop access, data theft and file collection. China-connected infrastructure is reported, but attacker origin and state sponsorship are not established.
A China-nexus, financially motivated commodity-crimeware cluster targeting Indian tax-related entities. It uses tax-notice phishing, ISO/IMG containers to bypass Mark-of-the-Web protections, DLL proxy sideloading via Notepad++, anti-analysis delays, UAC-prompt persistence/elevation, Donut shellcode loading, and a VenomRAT payload.
A China-nexus, financially motivated commodity-crimeware cluster targeting Indian tax entities with tax-notice phishing. It delivers an ISO image disguised as an IMG file, abuses a legitimately signed Notepad++ binary for DLL sideloading, employs anti-analysis delays and environment checks, establishes RunOnce persistence, and delivers VenomRAT through encrypted Donut shellcode.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.