Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware

https://hackernoon.imgix.net/images/InxBRjRIs6M1kdhuWcyNHiiUrxm1-kc83bcm.webp

An original threat intelligence investigation uncovering how trusted government infrastructure became an attack channel, placing banking organizations and public-sector systems at risk while revealing previously undocumented infrastructure relationships and actionable mitigation guidance for security leaders.

ANY.RUN analysts have uncovered an active PhantomEnigma campaign abusing compromised government infrastructure and fake police-themed documents to target banking and public-sector organizations in Brazil. Trusted emails and legitimate .gov.br links are helping the operation stay hidden.

By linking hundreds of seemingly unrelated sandbox analyses, the team exposed a coordinated operation that can delay containment, increase investigation costs, and raise the risk of fraud, data exposure, and operational disruption.

Key Takeaways

  • PhantomEnigma uses compromised Brazilian government systems for delivery:At least 20 .gov.br municipal and police portals were used to distribute malware, while compromised mailboxes allowed phishing emails to pass SPF, DKIM, and DMARC checks. These government systems are part of the delivery chain, not...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more