Mark RadarMARK RADAR
EN
Event File FINTECH Cyberattacks

PhantomEnigma Hijacks 20-Plus Brazilian Government Sites to Target Banks

1 reports · First detected 2026-07-24 · Last active 2026-07-24

PhantomEnigma is a Brazil-focused malware campaign targeting banks, including Banco do Brasil, and public-sector organizations. Attackers used compromised government portals and police mailboxes alongside fake documents such as “Ofício Polícia Civil” to distribute a modular Node.js backdoor. Because the messages originated from trusted infrastructure and passed SPF, DKIM and DMARC checks, legitimate-looking .gov.br links helped the campaign evade controls designed to detect spoofed email.

ANY.RUN disclosed the investigation on July 16, 2026, identifying at least 20 compromised municipal and police portals used as delivery infrastructure rather than confirmed end targets. Researchers linked 231 sandbox analyses to the broader build pattern between Jan. 15 and July 10, with activity peaking at 58 analyses in March and 66 in May. A live detonation on July 12 confirmed a second beacon generation and an active command-and-control domain, indicating the campaign remained operational.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)