PhantomEnigma Campaign Hijacks Brazilian Gov Websites for Malware Delivery

PhantomEnigma Campaign Hijacks Brazilian Gov Websites for Malware Delivery

First seen 22 Jul 2026, 18:55 UTC CybersecuritynewsHackernoonany.runintelligence.any.run 89% similarity 71.9

Article Content

Browse articles
ThreatCluster

The PhantomEnigma malware campaign has compromised over 20 Brazilian government websites, using them to deliver malware targeting banking and public-sector organizations. Attackers exploited legitimate government email accounts to send phishing emails with malicious payloads, leveraging trusted '.gov.br' links to evade detection. The operation has been active since January 2026, with various attack vectors including modular Node.js backdoors and PDF documents. Analysts report ongoing activity, with significant peaks in March and May. The campaign poses severe risks, including financial loss and data exposure, particularly affecting institutions like Banco do Brasil. Mitigation guidance has been provided for security leaders to address this threat.

Key Points: • PhantomEnigma has hijacked over 20 Brazilian government websites for malware delivery. • The campaign targets banking organizations, including Banco do Brasil, using trusted links. • Ongoing activity detected since January 2026, with multiple attack vectors employed.

ThreatCluster AI

Timeline

2026-01-15
PhantomEnigma campaign first observed
Initial activity of the PhantomEnigma campaign detected, targeting Brazilian government infrastructure.
Hackernoon
2026-02-01
PDF attack vector peaks
The PDF arm of the PhantomEnigma campaign peaked in February, targeting government systems.
Hackernoon
2026-03-01
Node.js backdoor activity peaks
Node.js/Inno Setup backdoor activity peaked in March, indicating increased malicious delivery.
Hackernoon
2026-05-01
Continued malware delivery observed
Ongoing malware delivery through compromised government infrastructure noted, with high activity levels.
Hackernoon
2026-07-10
Recent activity confirmed
Recent analyses confirm continued activity of the PhantomEnigma campaign, with multiple attack vectors in use.
Hackernoon

Community

Browse all →