
Hijacked .gov.br Sites Used as Malware Lures
Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to…
Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The campaigns used a “crypter” service called Cruciferra to hide malicious files and help malware run while avoiding detection. Targets included taxpayers and finance teams, as well as organizations in hospitality/travel, and multiple regulated sectors.
Researchers identified multiple unrelated phishing campaigns that shared a common tool: a crypter service called Cruciferra used to obscure malicious files and help malware run while avoiding detection. Phishing was the primary initial access vector across these campaigns, and messages could reach hundreds to thousands of recipients per run. One cluster used tax-themed lures that directed victims to attacker-controlled landing pages hosting ZIP files, with four such campaigns identified between April and early June 2026. Other campaigns impersonated the U.S. Social Security Administration to deliver malware, and separate messages used bed bug and guest complaint themes to target hospitality and travel organizations.
Each lure relied on a believable, high-stakes pretext rather than technical sophistication in the initial email. Tax notices and government agency messages exploit authority and urgency, pushing recipients to act before verifying the source. The hospitality-focused complaint lure worked because it mimicked an operational scenario, a guest complaint, that front desk and guest services staff are trained to respond to quickly. In all cases, the call to action was simple: click a link or open a file, which is a familiar and low-friction request that doesn't immediately signal danger.
Organizations can reduce risk by training finance and tax staff to verify refund or filing notices through known official channels rather than links in email. HR and payroll teams should be taught to treat unsolicited SSA-themed messages with skepticism and confirm authenticity independently, such as by calling a trusted number. Hospitality and guest services staff benefit from awareness that complaint-themed messages can be a malware delivery vector, especially when they push toward opening files or links outside normal complaint channels. Because these campaigns are opportunistic and can be sent at scale, a fast, low-friction reporting process for suspicious messages helps limit how far any single campaign spreads before it's contained.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Cruciferra is a crypter service used by multiple unrelated criminal clusters to hide malicious files and help malware evade detection while delivering RATs and information-stealers.
Observed lures included tax-themed messages directing victims to download ZIP files, emails impersonating the U.S. Social Security Administration, and messages about bed bug and guest complaints aimed at hospitality and travel organizations.
Targets spanned financial services, healthcare, government, education, manufacturing, and hospitality and travel, with roles including finance, tax, HR, payroll, and hospitality front desk staff.
The activity is assessed to be opportunistic, reaching anywhere between hundreds and thousands of messages per campaign.
Imagine this hits your inbox: “Your tax refund is delayed, download the attached ZIP to review your filing.” Behind emails like this is a malware loader called Cruciferra. It hides RATs and info-stealers inside files, pushed by tax lures, fake SSA notices, even “bed bugs and guest complaints” to hotels, sent in bursts of hundreds or thousands. Here’s the trick: the email link sends you to a lookalike site, definitely not the real portal, hosting a ZIP file. You think you’re grabbing tax documents or SSA info; you’re actually pulling down malware wrapped by Cruciferra. Your move: if any tax, SSA, or complaint email wants you to download a ZIP or open a file, stop, don’t click. Go to the official website or phone number you already trust and confirm it there, then report the email.

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to…

Proofpoint linked multiple real-world email campaigns to “Cruciferra,” a commercial crypter service that helps criminals hide malware from security tools. The…

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…