Researchers at ANY.RUN have uncovered the PhantomEnigma campaign, which hijacked over 20 Brazilian government websites to distribute modular backdoors and malware through highly convincing, authenticated phishing emails.
Key Points
- Attackers compromised legitimate .gov.br domains, including police and fire department portals, to host malicious redirects and bypass security filters.
- Phishing lures utilized fake police-themed documents and official notices that successfully passed SPF, DKIM, and DMARC authentication checks.
- The malware evolved from a browser-based banking threat into a sophisticated, modular Inno/Node.js backdoor capable of executing remote JavaScript commands.
- Once installed, the backdoor maintains persistence, collects system data, and communicates with rotating command-and-control infrastructure every 180 seconds.
- The campaign’s modular design allows operators to deploy secondary payloads, such as credential stealers or remote management tools, after the initial infection.