Researchers reported an active PhantomEnigma malware campaign that hijacked more than 20 Brazilian government-related websites and abused compromised mailboxes to distribute a modular Windows backdoor. Victims were lured with fake police or notary-style documents and redirected through compromised .gov.br and police-themed domains tied to municipal, judicial, fire department, and other public-sector infrastructure, giving the infection chain the appearance of legitimacy.
The malware was delivered as a Delphi-compiled Inno Setup installer that unpacked a patched Electron/Node.js application. Once installed, PhantomEnigma collected host information, established persistence, contacted rotating command-and-control servers roughly every 180 seconds, executed JavaScript, and downloaded additional payloads including stealers, loaders, and remote management tools. Investigators linked 231 sandbox analyses from January through July 2026 to the operation, indicating a sustained campaign that turned trusted government web assets into malware delivery infrastructure.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
ANY.RUN published research describing an active PhantomEnigma campaign that used at least 20 compromised Brazilian government-related and public-sector websites, along with compromised mailboxes, to deliver a modular Windows backdoor via fake document lures and a patched Electron/Node.js application.
ANY.RUN linked 231 sandbox analyses to the PhantomEnigma campaign over the period from January through July 2026, indicating sustained activity during that timeframe.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetrojan-killer.net
Open sourceany.run
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.