The Hacker Newsâ 31%
20+ Hijacked Government Websites Became an Attack Channel â 29%
By The Hacker Newsâ 58%
7/16/2026, 4:58:00 AM
BS Summary: This article contains 20 faulty reasoning types, including Pessimism Bias, Framing Effect, and Availability Heuristic, with Negativity Bias as the most egregious example at 9.6% saturation with 76 hits. Analysis detected 676 faulty-reasoning hits from 790 analyzed words, generating a BS Score of 33.2% and a BS Rank of â 29% (20,476 of 28,846 articles). This article is better (less manipulative) than 71.00% of the article peer group.
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions.Â
The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign putting banks and public agencies at risk.Â
By connecting hundreds of seemingly unrelated sandbox sessions, ANY.RUN researchers exposed the operationâs broader scope and showed how trusted .gov.br links and authenticated emails helped the activity remain hidden.Â
For the complete technical analysis, infrastructure details, indicators, and detection guidance, read the full PhantomEnigma investigation reportÂ
Trusted Government Infrastructure Became the LureÂ
The attack began with fake police-themed documents presented as official âOfĂcio PolĂcia Civilâ or âProcuração Digitalâ notices.Â
Some contained QR codes, while others directed recipients to links designed to look like legitimate government resources.Â
In several cases, the emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks.Â
That gave the messages a stronger appearance of legitimacy than ordinary spoofed phishing emails.Â
Victims were then redirected through compromised .gov.br hosts or police-themed lookalike domains before reaching the malicious installer.Â
The government systems were used as trusted delivery infrastructure, not necessarily as the final targets of the campaign.Â
Observed Government HostsÂ
Among the compromised systems observed during the investigation were timon.ma.gov[.]br, loginam.sesp.es.gov[.]br (state public security), aplicacao.cbm.mt.gov[.]br (fire department), prodoc.ap.gov[.]br, and others.Â
These legitimate municipal, public-security, and judicial portals were used at different stages of the delivery chain.Â
Several also appeared across more than one PhantomEnigma attack arm, helping researchers connect activity that initially looked unrelated.Â
PhantomEnigmaâs Evolution: Two Paths to Harder DetectionÂ
Timeline of PhantomEnigmaâs malisious activityÂ
The timeline shows one operation evolving along two main paths:Â
Delivery: PhantomEnigma moved from banking-focused activity in 2025 to abusing compromised .gov.br websites and email accounts in 2026.Â
This gave the campaign a more trusted route to victims without confirming a new target group.Â
Arsenal: The malware evolved from a browser-extension banker into a modular Inno/Node.js backdoor capable of executing JavaScript and delivering additional payloads.Â
For security teams, this combination creates a serious visibility gap.Â
Trusted infrastructure reduces suspicion, modular payloads can change after infection, and rotating C2 domains quickly make static blocklists outdated.Â
Behavioral analysis and continuous threat hunting provide more reliable coverage as the campaign evolves.Â
From Trusted Email to Full Compromise: The PhantomEnigma Attack ChainÂ
The analysis process of PhantomEnigma inside interactive sandboxÂ
Once a victim engaged with the lure, the campaign moved through a multi-stage infection chain:Â
Phishing email: A fake police-themed or official-document lure reaches the victim.Â
Trusted infrastructure: The link redirects through a compromised government host or police-themed lookalike domain.Â
Malicious installer: An Inno Setup, MSI, or another installer starts the infection.Â
Patched Electron application: Legitimate software loads a malicious index.js backdoor.Â
Backdoor activation: The malware collects system data, establishes persistence, and connects to rotating C2 infrastructure.Â
Second-stage delivery: The backdoor executes JavaScript or delivers stealers, loaders, RMM software, and other malware.Â
Business impact: The infection can lead to credential compromise, unauthorized access, fraud, data exposure, and operational disruption.Â
What Researchers Found Inside PhantomEnigmaâs BackdoorÂ
The sandbox sessions exposed more than a simple downloader.Â
Hidden inside a patched Boostnote and other applications was a modular index.js backdoor built to identify infected machines, maintain access, and deliver different payloads on demand.Â
Once activated, the backdoor could:Â
Collect the victimâs computer name, username, and system detailsÂ
Create a persistent machine ID and read a campaign tag stored beside the installerÂ
Establish persistence through login settingsÂ
Check for new commands every 180 secondsÂ
Execute JavaScript directly through eval()Â
Download and launch executable payloadsÂ
Communicate through multiple beacon formats across rotating infrastructureÂ
This modular design allows the operator to change the final payload without rebuilding the entire infection chain.Â
A system initially exposed to the same installer could later receive a stealer, loader, remote management tool, or another executable, making both detection and containment more difficult.Â
A Warning for Banks and Public AgenciesÂ
PhantomEnigma shows how attackers can turn trusted infrastructure into a detection advantage.Â
A legitimate government domain, authenticated email, or clean file verdict may lower suspicion even when the infection chain is already active.Â
For banks and public-sector organizations, the risk extends beyond one compromised endpoint.Â
Stolen credentials and persistent backdoor access can expose internal systems, sensitive data, and financial operations, while fragmented alerts delay containment.Â
Security teams should give employees a safe way to report suspicious official-looking messages and investigate them beyond the initial verdict.Â
Catching the trusted lure early can prevent credential theft, additional payload delivery, and a wider operational incident.Â
Get PhantomEnigma IOCs, infrastructure findings, and detection guidance to strengthen threat hunting and response.Â
Access Full ReportÂ
Speakers
1speaker3.7%attributed speech761writer words
Selected voice
100%flagged-word coverageANY.RUN
29 attributed words100% of attributed speech64% writer coverage
Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.
LoadingâŠ
LoadingâŠ
LoadingâŠ
LoadingâŠ
Analysis
Hover over highlighted words in the article to view the associated bias or fallacy analysis.