AUTO-UPDATED

20+ Hijacked Government Websites Became
an Attack Channel

Researchers at ANY.RUN have uncovered the PhantomEnigma campaign, which hijacked over 20 Brazilian government websites to distribute modular backdoors and malware through highly convincing, authenticated phishing emails.

Key Points

  • Attackers compromised legitimate .gov.br domains, including police and fire department portals, to host malicious redirects and bypass security filters.
  • Phishing lures utilized fake police-themed documents and official notices that successfully passed SPF, DKIM, and DMARC authentication checks.
  • The malware evolved from a browser-based banking threat into a sophisticated, modular Inno/Node.js backdoor capable of executing remote JavaScript commands.
  • Once installed, the backdoor maintains persistence, collects system data, and communicates with rotating command-and-control infrastructure every 180 seconds.
  • The campaign’s modular design allows operators to deploy secondary payloads, such as credential stealers or remote management tools, after the initial infection.

Why it Matters

This campaign demonstrates a significant shift in threat actor tactics by weaponizing trusted government infrastructure to evade traditional email and web security defenses. Organizations must move beyond static blocklists and implement behavioral analysis to detect these sophisticated, multi-stage attacks that exploit the perceived legitimacy of official communication channels.
Internet Published by info@thehackernews.com (The Hacker News)
Read original