
Tax and SSA Phish Push Cruciferra Malware Loader
Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…
Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to deliver malware. The lure used official-looking police-themed documents (sometimes with QR codes) and emails that could pass common email authentication checks, making the messages look legitimate. The goal was to get victims to click through trusted .gov.br infrastructure to a malicious installer that ultimately deployed a backdoor and additional payloads.
The PhantomEnigma campaign hijacked more than 20 Brazilian government websites and repurposed them as trusted stepping-stones for malware delivery. Victims received emails styled as official police or judicial notices, using document names like "Ofício Polícia Civil" and "Procuração Digital." Some messages included QR codes, while others contained links designed to look like legitimate government resources. Clicking through led victims across multiple redirects, sometimes through compromised .gov.br hosts or lookalike domains, before arriving at a malicious installer. That installer ultimately deployed a modular backdoor capable of executing JavaScript and delivering additional payloads.
The campaign combined several trust signals that are hard for an average recipient to question. Government-branded document names and police-themed language create urgency and authority. In several cases, the emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks, so standard email authentication offered no warning. Because the redirect chain passed through actual .gov.br infrastructure, the link itself appeared safe even though it was being used purely as delivery infrastructure rather than the final target.
These patterns matter across finance, accounts payable, legal, and general staff roles, since anyone handling official-looking correspondence could be targeted.
Organizations should reinforce that passing email authentication checks is not proof of safety, since compromised real accounts can still send authentic-looking phishing. Employees should be encouraged to treat unexpected official notices with skepticism, particularly when they push a link, QR code, or software installation to view a document. Security teams should give employees a safe way to report suspicious official-looking messages and investigate them beyond the initial verdict, since early reporting can prevent follow-on backdoor deployment and broader compromise. Awareness training should also highlight that a trusted-looking government domain can be part of an attack chain without being the ultimate target, so redirects and unexpected download prompts deserve scrutiny even on familiar-looking sites.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It was an active campaign in which more than 20 Brazilian government websites were hijacked and turned into malware delivery channels, using police-themed lures to trick victims into downloading a malicious installer.
In several cases the emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks, which made them look authentic even though the underlying accounts were compromised.
Attackers used official-looking notices such as "Ofício Polícia Civil" and "Procuração Digital," some of which included QR codes directing victims to lookalike or compromised government sites.
Passing SPF, DKIM, and DMARC only confirms the sending infrastructure is technically valid, not that the sender's account has not been compromised, so authenticated emails can still be malicious.
Imagine an email titled “Ofício Polícia Civil” that really comes from a trusted .gov.br address. In the PhantomEnigma campaign, more than 20 Brazilian government sites were hijacked so clicks on that link or QR code bounced through .gov.br pages and quietly delivered a malware installer. Here’s the aha: these emails used compromised mailboxes and even passed SPF, DKIM, and DMARC. The only real tell was weird behavior, multiple redirects and a demand to install software just to see a ‘Procuração Digital’. If you ever get an unexpected police or legal notice that wants you to click a link, scan a QR code, or install anything, stop and forward it to the security team for review.

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

Proofpoint linked multiple real-world email campaigns to “Cruciferra,” a commercial crypter service that helps criminals hide malware from security tools. The…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…