A newly discovered threat cluster, dubbed PAPERMILL, is leveraging tax-audit phishing emails to distribute VenomRAT malware to Windows users This article explores sandbox evasion checks. . The campaign employs ISO disk-image files, DLL sideloading, anti-analysis checks, and in-memory loaders to bypass common security measures.

JUMPSEC's Detection and Response Team detected the activity after a phishing email reached a client inbox, despite passing SPF, DKIM, and DMARC checks. The fake DLL exports only four curl functions required by the Notepad++ binary, making it appear compatible while launching the attack chain in the background. A signed Notepad++ executable is launched next. PAPERMILL employs multiple sandbox-evasion checks, including examining CPU cores, physical memory, disk space, system uptime, screen resolution, cursor movement, and recent keyboard or mouse activity.

The encrypted LIBCURL.DAT payload is decrypted through multiple stages, including XOR operations, bitwise changes, data reshuffling, and RC4. The resulting shellcode bears a resemblance to Donut, an open-source framework used to load .NET assemblies directly into memory, as mentioned by JUMPSEC. The indicators of compromise include: Category Indicator Type Indicator / Value Delivery Sender address / DKIM domain dfgfasd@hsaui[.

]cc Delivery Sending IP address 155.94.154.195