
Fake Screenshot ZIP Led to DigiCert Cert Theft
Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…
Researchers describe a real phishing-driven malware operation ("PhantomEnigma") that abuses compromised Brazilian government websites and mailboxes to appear trustworthy. Victims are lured with fake law-enforcement style documents (e.g., “Ofício” summons or “Procuração Digital”) and pushed to download and run a malicious installer that deploys a backdoor and can deliver additional payloads.
PhantomEnigma is a phishing-driven malware operation that abuses at least 20 legitimate Brazilian government portals (.gov.br) to host malicious files and redirect chains. The campaign starts with a phishing email sent through compromised official mailboxes, which lets the messages pass SPF, DKIM, and DMARC checks that would normally catch spoofed senders. Victims are lured with high-pressure law enforcement themed documents, including fake 'Ofício' (official summons) PDFs and 'Procuração Digital' (digital power of attorney) files. Clicking through leads to a Delphi-compiled installer, such as one named Procuracao_Digital.exe, which silently unpacks a patched Electron application and runs malicious JavaScript. The malware then establishes persistence through registry keys and connects to a rotating command-and-control infrastructure that can deliver additional payloads like stealers or remote access tools.
This operation succeeded largely because it borrowed trust from genuine infrastructure rather than trying to fake it. Because the links point to authentic government hosts, the malicious activity is difficult to distinguish from normal traffic, giving the operation an effective and trusted delivery channel. Combining compromised .gov.br portals with authentic email channels let the attackers bypass traditional reputation-based security controls that rely on domain or sender reputation. Layering in a high-pressure legal or law enforcement tone added urgency that discourages recipients from pausing to verify the request.
Defenders and employees, especially in finance, accounting, operations, HR, and executive assistant roles, should treat urgent legal or police-themed messages as a common manipulation tactic and verify requests through an independent, known channel rather than trusting SPF/DKIM/DMARC pass status or a government-looking domain alone. Since official notices should rarely require installing software, any workflow that ends in running an executable deserves scrutiny. Because command-and-control infrastructure for this operation rotates almost weekly, security programs should emphasize behavioral detection, such as flagging unexpected downloads and executable files, rather than relying solely on static blocklists.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
PhantomEnigma is a phishing-driven malware operation that abuses compromised Brazilian government mailboxes and .gov.br portals to distribute a backdoor via fake legal document lures.
The phishing emails were sent through compromised official mailboxes, which allowed them to pass SPF, DKIM, and DMARC checks that normally flag spoofed senders.
Victims received fake law enforcement themed documents such as an official summons ('Ofício') or a 'Procuração Digital' (digital power of attorney) that pushed them to download and run an installer.
Because the command-and-control infrastructure rotates almost weekly, static blacklists quickly become outdated, so defenders need to focus on behavioral red flags instead.
Imagine this: an email from a real .gov.br address, SPF, DKIM, DMARC all green, saying you’ve got an urgent “Ofício” or “Procuração Digital” to review. This is PhantomEnigma. They hijack at least 20 real Brazilian government portals, so your link really goes to a .gov.br site that offers a download named something like “Procuracao_Digital.exe”. Run it, and that installer quietly drops a patched Electron app, adds registry keys to stay on your machine, and connects out to rotating PhantomEnigma servers to pull more malware like stealers or RATs. Here’s the move: if an “official” Ofício or Procuração link makes you download an .exe instead of opening a PDF, stop and call the office using a number you already trust before you open anything.

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a…

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to…

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…