PhantomEnigma Phishes via Hijacked .gov.br Sites

Hack Read · High sophistication
Last updated July 30, 2026

Researchers describe a real phishing-driven malware operation ("PhantomEnigma") that abuses compromised Brazilian government websites and mailboxes to appear trustworthy. Victims are lured with fake law-enforcement style documents (e.g., “Ofício” summons or “Procuração Digital”) and pushed to download and run a malicious installer that deploys a backdoor and can deliver additional payloads.

How the attack worked

PhantomEnigma is a phishing-driven malware operation that abuses at least 20 legitimate Brazilian government portals (.gov.br) to host malicious files and redirect chains. The campaign starts with a phishing email sent through compromised official mailboxes, which lets the messages pass SPF, DKIM, and DMARC checks that would normally catch spoofed senders. Victims are lured with high-pressure law enforcement themed documents, including fake 'Ofício' (official summons) PDFs and 'Procuração Digital' (digital power of attorney) files. Clicking through leads to a Delphi-compiled installer, such as one named Procuracao_Digital.exe, which silently unpacks a patched Electron application and runs malicious JavaScript. The malware then establishes persistence through registry keys and connects to a rotating command-and-control infrastructure that can deliver additional payloads like stealers or remote access tools.

Why it succeeded

This operation succeeded largely because it borrowed trust from genuine infrastructure rather than trying to fake it. Because the links point to authentic government hosts, the malicious activity is difficult to distinguish from normal traffic, giving the operation an effective and trusted delivery channel. Combining compromised .gov.br portals with authentic email channels let the attackers bypass traditional reputation-based security controls that rely on domain or sender reputation. Layering in a high-pressure legal or law enforcement tone added urgency that discourages recipients from pausing to verify the request.

What to watch for

  • Emails referencing an 'Ofício' or 'Procuração Digital' that push urgent action
  • Government-branded links that lead to a downloadable installer rather than a viewable document
  • File downloads ending in .exe when a PDF or standard document was expected
  • Unexpected requests to install software to view an official notice

How to build resistance

Defenders and employees, especially in finance, accounting, operations, HR, and executive assistant roles, should treat urgent legal or police-themed messages as a common manipulation tactic and verify requests through an independent, known channel rather than trusting SPF/DKIM/DMARC pass status or a government-looking domain alone. Since official notices should rarely require installing software, any workflow that ends in running an executable deserves scrutiny. Because command-and-control infrastructure for this operation rotates almost weekly, security programs should emphasize behavioral detection, such as flagging unexpected downloads and executable files, rather than relying solely on static blocklists.

Key findings

  • Attackers abused “at least 20 legitimate Brazilian government portals” (.gov.br) to host malicious files and redirect chains.
  • Phishing emails were sent “through compromised official mailboxes,” allowing them to pass SPF/DKIM/DMARC checks.
  • Lures used “high-pressure law enforcement themes,” including fake “Ofício” (official summons) PDFs and “Procuração Digital” (digital power of attorney).
  • Victims were led to download an installer (example filename: “Procuracao_Digital.exe”) that unpacked a patched Electron app and executed malicious JavaScript.
  • The malware established persistence via registry keys and connected to a rotating command-and-control infrastructure, enabling delivery of additional payloads (e.g., stealers/RATs).

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, Operations, HR, Executive Assistants, All Employees.
  • Affected industries: Banking / Financial Services, Government / Public Sector.
  • Attack channels: email, website.
  • Impersonated: Brazilian government office (using a compromised .gov.br mailbox/portal), Government portal (.gov.br) / lookalike government site.

Red flags to watch for

  • High-pressure legal/police tone pushing urgent action
  • A download that is an .exe installer rather than a normal PDF document
  • Unexpected request to open a “government” link that leads to software installation
  • Email tries to borrow trust by using a government domain to lower suspicion
  • Link destination differs from expected workflow for official notices
  • File download leads to an installer/app rather than a document viewer
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is PhantomEnigma?

PhantomEnigma is a phishing-driven malware operation that abuses compromised Brazilian government mailboxes and .gov.br portals to distribute a backdoor via fake legal document lures.

How did PhantomEnigma bypass email security checks?

The phishing emails were sent through compromised official mailboxes, which allowed them to pass SPF, DKIM, and DMARC checks that normally flag spoofed senders.

What lures did the attackers use?

Victims received fake law enforcement themed documents such as an official summons ('Ofício') or a 'Procuração Digital' (digital power of attorney) that pushed them to download and run an installer.

Why is blocklisting ineffective against this threat?

Because the command-and-control infrastructure rotates almost weekly, static blacklists quickly become outdated, so defenders need to focus on behavioral red flags instead.

Read the video transcript

Imagine this: an email from a real .gov.br address, SPF, DKIM, DMARC all green, saying you’ve got an urgent “Ofício” or “Procuração Digital” to review. This is PhantomEnigma. They hijack at least 20 real Brazilian government portals, so your link really goes to a .gov.br site that offers a download named something like “Procuracao_Digital.exe”. Run it, and that installer quietly drops a patched Electron app, adds registry keys to stay on your machine, and connects out to rotating PhantomEnigma servers to pull more malware like stealers or RATs. Here’s the move: if an “official” Ofício or Procuração link makes you download an .exe instead of opening a PDF, stop and call the office using a number you already trust before you open anything.

Similar attacks

Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

July 17, 2026