The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers at ANY.RUN uncovered a campaign, dubbed PhantomEnigma, that hijacked more than 20 Brazilian government websites and used them as trusted channels to deliver malware.
- The attacks started with fake police-themed documents or emails, some passing standard email authentication checks, that redirected victims through compromised .gov.br hosts to malicious installers.
- The malware is a modular backdoor that collects system details, stays persistent on infected machines, and can deliver additional payloads like credential stealers and remote access tools.
- Banks and public agencies in Brazil are the main groups at risk, since stolen credentials and backdoor access can expose sensitive data and financial operations.
What to watch next
- Whether more compromised .gov.br sites are identified as the investigation expands.
- Changes in the campaign's delivery methods or malware payloads, which its modular design allows.
- New indicators of compromise or detection guidance from researchers as the campaign evolves.
Coverage1
1 report
English national1
All filed from India
Named Brazil · aplicacao.cbm.mt.gov.br · Banks · Boostnote · Brazilian Government · Inno Setup · loginam.sesp.es.gov.br · Node.js · prodoc.ap.gov.br · Public Agencies · timon.ma.gov.br · ANY.RUN · PhantomEnigma
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
