Hijacked .gov.br Sites Used as Malware Lures

The Hacker News · High sophistication
Last updated July 30, 2026

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to deliver malware. The lure used official-looking police-themed documents (sometimes with QR codes) and emails that could pass common email authentication checks, making the messages look legitimate. The goal was to get victims to click through trusted .gov.br infrastructure to a malicious installer that ultimately deployed a backdoor and additional payloads.

How the Attack Worked

The PhantomEnigma campaign hijacked more than 20 Brazilian government websites and repurposed them as trusted stepping-stones for malware delivery. Victims received emails styled as official police or judicial notices, using document names like "Ofício Polícia Civil" and "Procuração Digital." Some messages included QR codes, while others contained links designed to look like legitimate government resources. Clicking through led victims across multiple redirects, sometimes through compromised .gov.br hosts or lookalike domains, before arriving at a malicious installer. That installer ultimately deployed a modular backdoor capable of executing JavaScript and delivering additional payloads.

Why It Succeeded

The campaign combined several trust signals that are hard for an average recipient to question. Government-branded document names and police-themed language create urgency and authority. In several cases, the emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks, so standard email authentication offered no warning. Because the redirect chain passed through actual .gov.br infrastructure, the link itself appeared safe even though it was being used purely as delivery infrastructure rather than the final target.

What to Watch For

  • Unexpected official-looking legal or police notices arriving by email, especially ones demanding immediate action
  • Links or QR codes that lead through multiple redirects before displaying any actual document
  • Prompts to download and run an installer just to view what should be a simple document
  • Government-domain links that behave unusually, such as chaining to unrelated download pages

These patterns matter across finance, accounts payable, legal, and general staff roles, since anyone handling official-looking correspondence could be targeted.

How to Build Resistance

Organizations should reinforce that passing email authentication checks is not proof of safety, since compromised real accounts can still send authentic-looking phishing. Employees should be encouraged to treat unexpected official notices with skepticism, particularly when they push a link, QR code, or software installation to view a document. Security teams should give employees a safe way to report suspicious official-looking messages and investigate them beyond the initial verdict, since early reporting can prevent follow-on backdoor deployment and broader compromise. Awareness training should also highlight that a trusted-looking government domain can be part of an attack chain without being the ultimate target, so redirects and unexpected download prompts deserve scrutiny even on familiar-looking sites.

Key findings

  • “More than 20 Brazilian government websites were hijacked and turned into malware delivery channels” as part of an active PhantomEnigma campaign.
  • The lure used police-themed/official document names like “Ofício Polícia Civil” and “Procuração Digital,” including QR codes in some cases.
  • “In several cases, the emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks,” increasing trust.
  • Victims were “redirected through compromised .gov.br hosts or police-themed lookalike domains before reaching the malicious installer.”
  • The campaign used a multi-stage chain leading to a modular backdoor capable of executing JavaScript and delivering additional payloads.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounts Payable, Legal, Operations, All Employees, Security Awareness / IT.
  • Affected industries: Banking, Government / Public Sector.
  • Attack channels: email, website.
  • Impersonated: Brazilian police / government office (e.g., Polícia Civil).

Red flags to watch for

  • Unexpected “police-themed” legal/official notice sent by email
  • Link/QR code flow that redirects multiple times before showing any document
  • Prompts to download/run an installer (Inno Setup/MSI) just to view a document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the PhantomEnigma campaign?

It was an active campaign in which more than 20 Brazilian government websites were hijacked and turned into malware delivery channels, using police-themed lures to trick victims into downloading a malicious installer.

How did the phishing emails appear legitimate?

In several cases the emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks, which made them look authentic even though the underlying accounts were compromised.

What kind of documents were used as bait?

Attackers used official-looking notices such as "Ofício Polícia Civil" and "Procuração Digital," some of which included QR codes directing victims to lookalike or compromised government sites.

Why does passing email authentication checks not guarantee safety?

Passing SPF, DKIM, and DMARC only confirms the sending infrastructure is technically valid, not that the sender's account has not been compromised, so authenticated emails can still be malicious.

Read the video transcript

Imagine an email titled “Ofício Polícia Civil” that really comes from a trusted .gov.br address. In the PhantomEnigma campaign, more than 20 Brazilian government sites were hijacked so clicks on that link or QR code bounced through .gov.br pages and quietly delivered a malware installer. Here’s the aha: these emails used compromised mailboxes and even passed SPF, DKIM, and DMARC. The only real tell was weird behavior, multiple redirects and a demand to install software just to see a ‘Procuração Digital’. If you ever get an unexpected police or legal notice that wants you to click a link, scan a QR code, or install anything, stop and forward it to the security team for review.

Similar attacks