PhantomEnigma Infects Organizations with Malware via Hijacked Government Websites

https://hackread.com/wp-content/uploads/2026/07/phantomenigma-infects-malware-hijack-gov-sites-6-1024x683.jpg

Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.

ANY.RUN’s threat research team has uncovered a highly sophisticated and resilient malware operation known as PhantomEnigma, which specifically targets banking and public-sector organizations. By leveraging compromised .gov.br portals and authentic email channels, the operation effectively bypasses traditional reputation-based security controls, posing a severe threat to organizations that rely on domain trust to verify incoming communications.

Antivirus& Malware

How PhantomEnigma Uses Government Sites to Distribute Malware

The core of the PhantomEnigma strategy is the systemic abuse of at least 20 legitimate Brazilian government portals (The full list is available in ANY.RUN’s TI Reports), including municipal and police websites.

The attackers hijack these official platforms to host malicious files and manage redirect chains, ensuring that every link sent to a victim carries the weight of a trusted domain.including municipal and police...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/4DKiUF32YY5BX96h6fscGL-2560-80.jpg

Cherokee Nation joins list of tribes banning data centers on tribal lands due to water, energy, noise, and cultural resource protection concerns — and all new projects require ‘early consultation’

* The Cherokee Nation has placed a moratorium on new data centers on tribal lands * Citizens say they are concerned about the impact of new projects on the local areas * Data centers projects on non-tribal land will not be granted support by the Cherokee Nation unless they are given early consultation