When Trusted Gov Infrastructure Becomes an Attack Channel: PhantomEnigma Puts Banks at Risk
ID: e24e1ee6-ce14-587e-8cfa-baab75e8aa98
STIX ID: report--e24e1ee6-ce14-587e-8cfa-baab75e8aa98
Feed Name: Cyber Press
Threat Score
ANY.RUN analyzed the PhantomEnigma campaign that abused compromised Brazilian government websites and phishing to deliver installers (Inno Setup/MSI) and a modular Node.js backdoor (index.js). The campaign focuses on credential theft against banking organizations, enabling fraud, unauthorized access, data exposure, and persistent footholds; ANY.RUN recommends behavioral sandboxing and continuous monitoring to reduce detection delays and business impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
