CyberSecurityBoardThreat Intel · CVEs · Products
Malware

20+ Hijacked Brazilian Government Websites Used as Malware Delivery Channels in PhantomEnigma Campaign

July 16, 2026

More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign putting banks and public agencies at risk.

The attack began with fake police-themed documents presented as official notices. Some contained QR codes, while others directed recipients to links designed to look like legitimate government resources. In several cases, the emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks. Victims were then redirected through compromised .gov.br hosts or police-themed lookalike domains before reaching the malicious installer.

Observed compromised government hosts included timon.ma.gov.br, loginam.sesp.es.gov.br, aplicacao.cbm.mt.gov.br, and prodoc.ap.gov.br. These legitimate municipal, public-security, and judicial portals were used at different stages of the delivery chain.

PhantomEnigma evolved from a browser-extension banker into a modular Inno/Node.js backdoor capable of executing JavaScript and delivering additional payloads. The infection chain involves a phishing email, redirection through trusted infrastructure, a malicious installer, a patched Electron application (e.g., Boostnote) loading a malicious index.js backdoor, backdoor activation, second-stage delivery, and business impact such as credential compromise and fraud.

The backdoor collects system data, establishes persistence, connects to rotating C2 infrastructure, and can execute JavaScript or deliver stealers, loaders, RMM software, and other malware. For banks and public-sector organizations, the risk extends beyond one compromised endpoint. Security teams should give employees a safe way to report suspicious official-looking messages and investigate them beyond the initial verdict.

Attack groups: PhantomEnigma

Malware: PhantomEnigma

Companies: ANY.RUN

Products: Boostnote