Hackernoon
PhantomEnigma Campaign Hijacks Brazilian Gov Websites for Malware Delivery
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The PhantomEnigma malware campaign has compromised over 20 Brazilian government websites, using them to deliver malware targeting banking and public-sector organizations. Attackers exploited legitimate government email accounts to send phishing emails with malicious payloads, leveraging trusted '.gov.br' links to evade detection. The operation has been active since January 2026, with various attack vectors including modular Node.js backdoors and PDF documents. Analysts report ongoing activity, with significant peaks in March and May. The campaign poses severe risks, including financial loss and data exposure, particularly affecting institutions like Banco do Brasil. Mitigation guidance has been provided for security leaders to address this threat.
Key Points: • PhantomEnigma has hijacked over 20 Brazilian government websites for malware delivery. • The campaign targets banking organizations, including Banco do Brasil, using trusted links. • Ongoing activity detected since January 2026, with multiple attack vectors employed.