PhantomEnigma Phishes via Hijacked .gov.br Sites

Hack Read · High sophistication
Last updated July 30, 2026

Researchers describe a real phishing-driven malware operation ("PhantomEnigma") that abuses compromised Brazilian government websites and mailboxes to appear trustworthy. Victims are lured with fake law-enforcement style documents (e.g., “Ofício” summons or “Procuração Digital”) and pushed to download and run a malicious installer that deploys a backdoor and can deliver additional payloads.

How the attack worked

PhantomEnigma is a phishing-driven malware operation that abuses at least 20 legitimate Brazilian government portals (.gov.br) to host malicious files and redirect chains. The campaign starts with a phishing email sent through compromised official mailboxes, which lets the messages pass SPF, DKIM, and DMARC checks that would normally catch spoofed senders. Victims are lured with high-pressure law enforcement themed documents, including fake 'Ofício' (official summons) PDFs and 'Procuração Digital' (digital power of attorney) files. Clicking through leads to a Delphi-compiled installer, such as one named Procuracao_Digital.exe, which silently unpacks a patched Electron application and runs malicious JavaScript. The malware then establishes persistence through registry keys and connects to a rotating command-and-control infrastructure that can deliver additional payloads like stealers or remote access tools.

Why it succeeded

This operation succeeded largely because it borrowed trust from genuine infrastructure rather than trying to fake it. Because the links point to authentic government hosts, the malicious activity is difficult to distinguish from normal traffic, giving the operation an effective and trusted delivery channel. Combining compromised .gov.br portals with authentic email channels let the attackers bypass traditional reputation-based security controls that rely on domain or sender reputation. Layering in a high-pressure legal or law enforcement tone added urgency that discourages recipients from pausing to verify the request.

What to watch for

  • Emails referencing an 'Ofício' or 'Procuração Digital' that push urgent action
  • Government-branded links that lead to a downloadable installer rather than a viewable document
  • File downloads ending in .exe when a PDF or standard document was expected
  • Unexpected requests to install software to view an official notice

How to build resistance

Defenders and employees, especially in finance, accounting, operations, HR, and executive assistant roles, should treat urgent legal or police-themed messages as a common manipulation tactic and verify requests through an independent, known channel rather than trusting SPF/DKIM/DMARC pass status or a government-looking domain alone. Since official notices should rarely require installing software, any workflow that ends in running an executable deserves scrutiny. Because command-and-control infrastructure for this operation rotates almost weekly, security programs should emphasize behavioral detection, such as flagging unexpected downloads and executable files, rather than relying solely on static blocklists.

Key findings

  • Attackers abused “at least 20 legitimate Brazilian government portals” (.gov.br) to host malicious files and redirect chains.
  • Phishing emails were sent “through compromised official mailboxes,” allowing them to pass SPF/DKIM/DMARC checks.
  • Lures used “high-pressure law enforcement themes,” including fake “Ofício” (official summons) PDFs and “Procuração Digital” (digital power of attorney).
  • Victims were led to download an installer (example filename: “Procuracao_Digital.exe”) that unpacked a patched Electron app and executed malicious JavaScript.
  • The malware established persistence via registry keys and connected to a rotating command-and-control infrastructure, enabling delivery of additional payloads (e.g., stealers/RATs).

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, Operations, HR, Executive Assistants, All Employees.
  • Affected industries: Banking / Financial Services, Government / Public Sector.
  • Attack channels: email, website.
  • Impersonated: Brazilian government office (using a compromised .gov.br mailbox/portal), Government portal (.gov.br) / lookalike government site.

Red flags to watch for

  • High-pressure legal/police tone pushing urgent action
  • A download that is an .exe installer rather than a normal PDF document
  • Unexpected request to open a “government” link that leads to software installation
  • Email tries to borrow trust by using a government domain to lower suspicion
  • Link destination differs from expected workflow for official notices
  • File download leads to an installer/app rather than a document viewer
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is PhantomEnigma?

PhantomEnigma is a phishing-driven malware operation that abuses compromised Brazilian government mailboxes and .gov.br portals to distribute a backdoor via fake legal document lures.

How did PhantomEnigma bypass email security checks?

The phishing emails were sent through compromised official mailboxes, which allowed them to pass SPF, DKIM, and DMARC checks that normally flag spoofed senders.

What lures did the attackers use?

Victims received fake law enforcement themed documents such as an official summons ('Ofício') or a 'Procuração Digital' (digital power of attorney) that pushed them to download and run an installer.

Why is blocklisting ineffective against this threat?

Because the command-and-control infrastructure rotates almost weekly, static blacklists quickly become outdated, so defenders need to focus on behavioral red flags instead.

Read the video transcript

Imagine this: an email from a real .gov.br address, SPF, DKIM, DMARC all green, saying you’ve got an urgent “Ofício” or “Procuração Digital” to review. This is PhantomEnigma. They hijack at least 20 real Brazilian government portals, so your link really goes to a .gov.br site that offers a download named something like “Procuracao_Digital.exe”. Run it, and that installer quietly drops a patched Electron app, adds registry keys to stay on your machine, and connects out to rotating PhantomEnigma servers to pull more malware like stealers or RATs. Here’s the move: if an “official” Ofício or Procuração link makes you download an .exe instead of opening a PDF, stop and call the office using a number you already trust before you open anything.

Similar attacks

Fake Screenshot ZIP Led to DigiCert Cert Theft

Fake Screenshot ZIP Led to DigiCert Cert Theft

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization…

July 17, 2026
Tax and SSA Phish Push Cruciferra Malware Loader

Tax and SSA Phish Push Cruciferra Malware Loader

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The campaigns used a “crypter” service called Cruciferra to hide malicious files and help malware run while avoiding detection. Targets included…

July 27, 2026
Govt-Themed Phishing Spreads Cruciferra Malware

Govt-Themed Phishing Spreads Cruciferra Malware

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a “crypter” service called Cruciferra to help common remote-access and data-stealing malware evade detection. Financial services, healthcare,…

July 21, 2026
Hijacked .gov.br Sites Used as Malware Lures

Hijacked .gov.br Sites Used as Malware Lures

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to deliver malware. The lure used official-looking police-themed documents (sometimes with QR codes) and emails that could pass common email…

July 16, 2026
Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026