Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links
ID: dccb187e-8bcd-54bd-96e5-b11202e97f6d
STIX ID: report--dccb187e-8bcd-54bd-96e5-b11202e97f6d
Feed Name: cybersecurityNews.com
PhantomEnigma is an active, high-risk malware campaign abusing compromised Brazilian government websites and mailboxes to deliver Delphi/Inno Setup installers that deploy a patched Electron application containing a JavaScript backdoor (index.js). The operation uses convincing police and notary phishing lures (including QR-code quishing), rotates C2 domains and IPs frequently, has been observed in 231 sandbox sessions across multiple backdoor generations, and is capable of data exfiltration, reconnaissance, and follow-on stealer/RAT payloads—posing significant risk to banking and public-sector organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
