logo

PhantomEnigma Infects Organizations with Malware via Hijacked Government Websites

ID: 386e6553-34ae-5ee9-a22b-4a8307002ccd

STIX ID: report--386e6553-34ae-5ee9-a22b-4a8307002ccd

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-07-28

Date Updated: 2026-08-06

Author: Owais Sultan

...
...

PhantomEnigma is a sophisticated phishing and malware campaign that leverages compromised Brazilian .gov.br portals and authentic government email accounts to distribute Delphi-built installers that unpack a patched Electron backdoor (malicious index.js). The operation targets banking and public-sector organizations to harvest credentials and deploy stealers/remote tools, uses trusted domains to evade reputation controls, rotates C2 infrastructure frequently, and has been linked across hundreds of observed sandbox sessions via a consistent build-chain fingerprint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.