PhantomEnigma Infects Organizations with Malware via Hijacked Government Websites
Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.
ANY.RUN’s threat research team has uncovered a highly sophisticated and resilient malware operation known as PhantomEnigma, which specifically targets banking and public-sector organizations. By leveraging compromised .gov.br portals and authentic email channels, the operation effectively bypasses traditional reputation-based security controls, posing a severe threat to organizations that rely on domain trust to verify incoming communications.
Antivirus& Malware
How PhantomEnigma Uses Government Sites to Distribute Malware
The core of the PhantomEnigma strategy is the systemic abuse of at least 20 legitimate Brazilian government portals (The full list is available in ANY.RUN’s TI Reports), including municipal and police websites.
The attackers hijack these official platforms to host malicious files and manage redirect chains, ensuring that every link sent to a victim carries the weight of a trusted domain.including municipal and police...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE