Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

TrickBot Ditches HTTP for DNS Tunneling in Latest Variant

July 22, 2026

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

July 22, 2026

Ubuntu snap-confine Vulnerability Enables Local Root Access

July 22, 2026
Facebook X (Twitter) Instagram
Wednesday, July 22
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»20+ Hijacked Government Websites Became
an Attack Channel
News

20+ Hijacked Government Websites Became
an Attack Channel

Team-CWDBy Team-CWDJuly 22, 2026No Comments5 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions.

The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign putting banks and public agencies at risk.

By connecting hundreds of seemingly unrelated sandbox sessions, ANY.RUN researchers exposed the operation’s broader scope and showed how trusted .gov.br links and authenticated emails helped the activity remain hidden.

Trusted Government Infrastructure Became the Lure

The attack began with fake police-themed documents presented as official “Ofício Polícia Civil” or “Procuração Digital” notices. Some contained QR codes, while others directed recipients to links designed to look like legitimate government resources.

Fake police-themed document analyzed inside ANY.RUN sandbox for full visibility into PhantomEnigma attack

In several cases, the emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks. That gave the messages a stronger appearance of legitimacy than ordinary spoofed phishing emails.

Victims were then redirected through compromised .gov.br hosts or police-themed lookalike domains before reaching the malicious installer. The government systems were used as trusted delivery infrastructure, not necessarily as the final targets of the campaign.

Observed Government Hosts

Among the compromised systems observed during the investigation were timon.ma.gov[.]br, loginam.sesp.es.gov[.]br (state public security), aplicacao.cbm.mt.gov[.]br (fire department), prodoc.ap.gov[.]br, and others.

TI Lookup query that involves compromised government hosts

These legitimate municipal, public-security, and judicial portals were used at different stages of the delivery chain. Several also appeared across more than one PhantomEnigma attack arm, helping researchers connect activity that initially looked unrelated.

PhantomEnigma’s Evolution: Two Paths to Harder Detection

Timeline of PhantomEnigma’s malisious activity

The timeline shows one operation evolving along two main paths:

Delivery: PhantomEnigma moved from banking-focused activity in 2025 to abusing compromised .gov.br websites and email accounts in 2026. This gave the campaign a more trusted route to victims without confirming a new target group.

Arsenal: The malware evolved from a browser-extension banker into a modular Inno/Node.js backdoor capable of executing JavaScript and delivering additional payloads.

For security teams, this combination creates a serious visibility gap. Trusted infrastructure reduces suspicion, modular payloads can change after infection, and rotating C2 domains quickly make static blocklists outdated. Behavioral analysis and continuous threat hunting provide more reliable coverage as the campaign evolves.

From Trusted Email to Full Compromise: The PhantomEnigma Attack Chain

The analysis process of PhantomEnigma inside interactive sandbox

Once a victim engaged with the lure, the campaign moved through a multi-stage infection chain:

  1. Phishing email: A fake police-themed or official-document lure reaches the victim.
  2. Trusted infrastructure: The link redirects through a compromised government host or police-themed lookalike domain.
  3. Malicious installer: An Inno Setup, MSI, or another installer starts the infection.
  4. Patched Electron application: Legitimate software loads a malicious index.js backdoor.
  5. Backdoor activation: The malware collects system data, establishes persistence, and connects to rotating C2 infrastructure.
  6. Second-stage delivery: The backdoor executes JavaScript or delivers stealers, loaders, RMM software, and other malware.
  7. Business impact: The infection can lead to credential compromise, unauthorized access, fraud, data exposure, and operational disruption.

What Researchers Found Inside PhantomEnigma’s Backdoor

The sandbox sessions exposed more than a simple downloader. Hidden inside a patched Boostnote and other applications was a modular index.js backdoor built to identify infected machines, maintain access, and deliver different payloads on demand.

Once activated, the backdoor could:

  • Collect the victim’s computer name, username, and system details
  • Create a persistent machine ID and read a campaign tag stored beside the installer
  • Establish persistence through login settings
  • Check for new commands every 180 seconds
  • Execute JavaScript directly through eval()
  • Download and launch executable payloads
  • Communicate through multiple beacon formats across rotating infrastructure

This modular design allows the operator to change the final payload without rebuilding the entire infection chain. A system initially exposed to the same installer could later receive a stealer, loader, remote management tool, or another executable, making both detection and containment more difficult.

A Warning for Banks and Public Agencies

PhantomEnigma shows how attackers can turn trusted infrastructure into a detection advantage. A legitimate government domain, authenticated email, or clean file verdict may lower suspicion even when the infection chain is already active.

For banks and public-sector organizations, the risk extends beyond one compromised endpoint. Stolen credentials and persistent backdoor access can expose internal systems, sensitive data, and financial operations, while fragmented alerts delay containment.

Security teams should give employees a safe way to report suspicious official-looking messages and investigate them beyond the initial verdict. Catching the trusted lure early can prevent credential theft, additional payload delivery, and a wider operational incident.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.





Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAI Can Find Bugs, But Human Knowledge Still Proves Them
Next Article OpenAI Claims Its AI Models Went Rogue and Hacked Another Company
Team-CWD
  • Website

Related Posts

News

TrickBot Ditches HTTP for DNS Tunneling in Latest Variant

July 22, 2026
News

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

July 22, 2026
News

OpenAI Claims Its AI Models Went Rogue and Hacked Another Company

July 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why geopolitical turmoil is a gift for scammers, and how to stay safe

May 15, 2026

Is it time for internet services to adopt identity verification?

January 14, 2026

Here’s how to avoid a ‘second strike’

April 11, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.