Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

PAPERMILL: Tracking an Emerging China-Nexus Malware Factory

JUMPSEC’s DART (Detection & Response Team) raised an alert to the Threat Research team regarding a specific ticket that arrived in a clients’ inbox, passing SPF, DKIM, and DMARC. The email contained an attachment and a subject which spoke about Tax Audits, that attachment, named “Tax_Notice_45594.exe” is not actually an exe but instead an.ISO. On the surface this looks like a fairly typical phishing lure, but the delivery mechanism underneath is anything but.