PhantomEnigma Hijacks 20-Plus Brazilian Government Sites to Target Banks
PhantomEnigma is a Brazil-focused malware campaign targeting banks, including Banco do Brasil, and public-sector organizations. Attackers used compromised government portals and police mailboxes alongside fake documents such as “Ofício Polícia Civil” to distribute a modular Node.js backdoor. Because the messages originated from trusted infrastructure and passed SPF, DKIM and DMARC checks, legitimate-looking .gov.br links helped the campaign evade controls designed to detect spoofed email.
ANY.RUN disclosed the investigation on July 16, 2026, identifying at least 20 compromised municipal and police portals used as delivery infrastructure rather than confirmed end targets. Researchers linked 231 sandbox analyses to the broader build pattern between Jan. 15 and July 10, with activity peaking at 58 analyses in March and 66 in May. A live detonation on July 12 confirmed a second beacon generation and an active command-and-control domain, indicating the campaign remained operational.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.