logo

Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links

ID: dccb187e-8bcd-54bd-96e5-b11202e97f6d

STIX ID: report--dccb187e-8bcd-54bd-96e5-b11202e97f6d

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Guru Baran

...
...

PhantomEnigma is an active, high-risk malware campaign abusing compromised Brazilian government websites and mailboxes to deliver Delphi/Inno Setup installers that deploy a patched Electron application containing a JavaScript backdoor (index.js). The operation uses convincing police and notary phishing lures (including QR-code quishing), rotates C2 domains and IPs frequently, has been observed in 231 sandbox sessions across multiple backdoor generations, and is capable of data exfiltration, reconnaissance, and follow-on stealer/RAT payloads—posing significant risk to banking and public-sector organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.