{"id":1831,"date":"2026-07-16T17:23:50","date_gmt":"2026-07-16T17:23:50","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1831"},"modified":"2026-07-16T17:23:50","modified_gmt":"2026-07-16T17:23:50","slug":"20-hijacked-government-websites-became-an-attack-channel","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1831","title":{"rendered":"20+ Hijacked Government Websites Became\u2028an Attack Channel"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">The Hacker News<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 16, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Endpoint Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgs_Ix6AmdT0f-NuPj2BLNRcSaOhWHf5pPdDuwR0eykvHCnOmoHUhq5Z2axM2GJX9gX5A3FlesfKuynGTsj012HNIJZURuZ8S7uCfa7_cSXIZDWC1donHjiQbkNr3jNLSq8B2PGpUG24fddwOaG2POjEQuvlrVEnp3yPa1F3tV2fpYDVQHEsaIHbnShUuQ\/s1700-e365\/hacked.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active <b>PhantomEnigma <\/b>campaign uncovered by <a href=\"https:\/\/any.run\/?utm_source=the+hacker+news&amp;utm_medium=article&amp;utm_campaign=hijacked+websites&amp;utm_content=landing&amp;utm_term=160726\" target=\"_blank\">ANY.RUN<\/a>, a leading provider of interactive malware analysis and threat intelligence solutions.<\/p>\n<p>The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign putting banks and public agencies at risk.<\/p>\n<p>By connecting hundreds of seemingly unrelated sandbox sessions, ANY.RUN researchers exposed the operation\u2019s broader scope and showed how trusted .gov.br links and authenticated emails helped the activity remain hidden.<\/p>\n<div class=\"article-board\">\n<p><em>For the complete technical analysis, infrastructure details, indicators, and detection guidance, read the <a href=\"https:\/\/any.run\/cybersecurity-blog\/phantomenigma-research\/?utm_source=the+hacker+news&amp;utm_medium=article&amp;utm_campaign=hijacked+websites&amp;utm_content=blog&amp;utm_term=160726\" target=\"_blank\">full PhantomEnigma investigation report<\/a><\/em><\/p>\n<\/div>\n<h2>Trusted Government Infrastructure Became the Lure<\/h2>\n<p>The attack began with fake police-themed documents presented as official \u201cOf\u00edcio Pol\u00edcia Civil\u201d or \u201cProcura\u00e7\u00e3o Digital\u201d notices. Some contained QR codes, while others directed recipients to links designed to look like legitimate government resources.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiS6yDw8gAJEfaIhWbCPAicAqgEu0BMZ_dXO6KAhaAoPus4eg87j0-FjoqBr3n20oH9sce5VgJtGQe1M9sk0B7dA2tB_K3SlK7ac6_UaIxeqqkmtNcSywtCMYGVUSDE1xfxU8r8hpQdrWGc4vxwGRJjWZON7heiYE-wVS8nC6NTHskmSw-50Duag1wgbX0\/s1700-e365\/1.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiS6yDw8gAJEfaIhWbCPAicAqgEu0BMZ_dXO6KAhaAoPus4eg87j0-FjoqBr3n20oH9sce5VgJtGQe1M9sk0B7dA2tB_K3SlK7ac6_UaIxeqqkmtNcSywtCMYGVUSDE1xfxU8r8hpQdrWGc4vxwGRJjWZON7heiYE-wVS8nC6NTHskmSw-50Duag1wgbX0\/s1700-e365\/1.png\" alt=\"\" border=\"0\" data-original-height=\"508\" data-original-width=\"901\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">Fake police-themed document analyzed inside ANY.RUN sandbox for full visibility into PhantomEnigma attack<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>In several cases, the emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks. That gave the messages a stronger appearance of legitimacy than ordinary spoofed phishing emails.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Victims were then redirected through compromised .gov.br hosts or police-themed lookalike domains before reaching the malicious installer. The government systems were used as trusted delivery infrastructure, not necessarily as the final targets of the campaign.<\/p>\n<h3>Observed Government Hosts<\/h3>\n<p>Among the compromised systems observed during the investigation were timon.ma.gov[.]br, loginam.sesp.es.gov[.]br (state public security), aplicacao.cbm.mt.gov[.]br (fire department), prodoc.ap.gov[.]br, and others.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCs8KTadxz4wegYdQURkJ09ChGrFmzV7p9auvDn_MfyxhGMexgFLJy6x3jYBbdL00JahpVc9OQ_1mfL9OAMUMYKmc_4aN_Yd6TdqaXip8GdD5otdre9iS8IuObqRAjHL-7nWIMCfuGTPCyTgFhyphenhyphenRrCsYsCC9VQPU6DiWxZ0ljthfU3O_oFeCcj4ThI8eg\/s1700-e365\/2.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCs8KTadxz4wegYdQURkJ09ChGrFmzV7p9auvDn_MfyxhGMexgFLJy6x3jYBbdL00JahpVc9OQ_1mfL9OAMUMYKmc_4aN_Yd6TdqaXip8GdD5otdre9iS8IuObqRAjHL-7nWIMCfuGTPCyTgFhyphenhyphenRrCsYsCC9VQPU6DiWxZ0ljthfU3O_oFeCcj4ThI8eg\/s1700-e365\/2.png\" alt=\"\" border=\"0\" data-original-height=\"516\" data-original-width=\"901\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">TI Lookup query that involves compromised government hosts<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>These legitimate municipal, public-security, and judicial portals were used at different stages of the delivery chain. Several also appeared across more than one PhantomEnigma attack arm, helping researchers connect activity that initially looked unrelated.<\/p>\n<h2>PhantomEnigma\u2019s Evolution: Two Paths to Harder Detection<\/h2>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEicxDrh4bHJFBURe-TomnpaBKByXGZDKIrU5Lu1h_nnL0LTRfohZdedMNLMo8fgF_kb3mqffPjKJDWTWQhx1EqME5HRE2ovjNxBbrFULqCp-_PuaLG2fSPmb42IP4DXQrUDge1ZjRGJgojbPkimlQxb2E5QikOX-Reny9pMBUanDz2ZBJhcnKB7ncWtM1w\/s1700-e365\/3.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEicxDrh4bHJFBURe-TomnpaBKByXGZDKIrU5Lu1h_nnL0LTRfohZdedMNLMo8fgF_kb3mqffPjKJDWTWQhx1EqME5HRE2ovjNxBbrFULqCp-_PuaLG2fSPmb42IP4DXQrUDge1ZjRGJgojbPkimlQxb2E5QikOX-Reny9pMBUanDz2ZBJhcnKB7ncWtM1w\/s1700-e365\/3.png\" alt=\"\" border=\"0\" data-original-height=\"507\" data-original-width=\"901\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">Timeline of PhantomEnigma\u2019s malisious activity<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The timeline shows one operation evolving along two main paths:<\/p>\n<p><strong>Delivery:<\/strong> PhantomEnigma moved from banking-focused activity in 2025 to abusing compromised .gov.br websites and email accounts in 2026. This gave the campaign a more trusted route to victims without confirming a new target group.<\/p>\n<p><strong>Arsenal:<\/strong> The malware evolved from a browser-extension banker into a modular Inno\/Node.js backdoor capable of executing JavaScript and delivering additional payloads.<\/p>\n<p>For security teams, this combination creates a serious visibility gap. Trusted infrastructure reduces suspicion, modular payloads can change after infection, and rotating C2 domains quickly make static blocklists outdated. Behavioral analysis and continuous threat hunting provide more reliable coverage as the campaign evolves.<\/p>\n<h2>From Trusted Email to Full Compromise: The PhantomEnigma Attack Chain<\/h2>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjHwkvJsUjNfQrYdKLS0i-zDBL_xwpHHt0jSsyUBopBJG0YwlqGvq8RGr379QebkgEYGo2tYHUfotTRwXaDgJauUn9W-Vufevfhut3ARrce8rZNpEO1-NCHP3PsActy_RiBi4Mk5nuUR4PiDu6OBICrJgOZ6h61uTP0yHxWKXFrHj90W0tGyvNTGYH3DNc\/s1700-e365\/4.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjHwkvJsUjNfQrYdKLS0i-zDBL_xwpHHt0jSsyUBopBJG0YwlqGvq8RGr379QebkgEYGo2tYHUfotTRwXaDgJauUn9W-Vufevfhut3ARrce8rZNpEO1-NCHP3PsActy_RiBi4Mk5nuUR4PiDu6OBICrJgOZ6h61uTP0yHxWKXFrHj90W0tGyvNTGYH3DNc\/s1700-e365\/4.png\" alt=\"\" border=\"0\" data-original-height=\"501\" data-original-width=\"901\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">The analysis process of PhantomEnigma inside interactive sandbox<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Once a victim engaged with the lure, the campaign moved through a multi-stage infection chain:<\/p>\n<ol>\n<li><strong>Phishing email:<\/strong> A fake police-themed or official-document lure reaches the victim.<\/li>\n<li><strong>Trusted infrastructure:<\/strong> The link redirects through a compromised government host or police-themed lookalike domain.<\/li>\n<li><strong>Malicious installer:<\/strong> An Inno Setup, MSI, or another installer starts the infection.<\/li>\n<li><strong>Patched Electron application:<\/strong> Legitimate software loads a malicious index.js backdoor.<\/li>\n<li><strong>Backdoor activation:<\/strong> The malware collects system data, establishes persistence, and connects to rotating C2 infrastructure.<\/li>\n<li><strong>Second-stage delivery:<\/strong> The backdoor executes JavaScript or delivers stealers, loaders, RMM software, and other malware.<\/li>\n<li><strong>Business impact:<\/strong> The infection can lead to credential compromise, unauthorized access, fraud, data exposure, and operational disruption.<\/li>\n<\/ol>\n<h2>What Researchers Found Inside PhantomEnigma\u2019s Backdoor<\/h2>\n<p>The sandbox sessions exposed more than a simple downloader. Hidden inside a patched Boostnote and other applications was a modular index.js backdoor built to identify infected machines, maintain access, and deliver different payloads on demand.<\/p>\n<p>Once activated, the backdoor could:<\/p>\n<ul>\n<li>Collect the victim\u2019s computer name, username, and system details<\/li>\n<li>Create a persistent machine ID and read a campaign tag stored beside the installer<\/li>\n<li>Establish persistence through login settings<\/li>\n<li>Check for new commands every 180 seconds<\/li>\n<li>Execute JavaScript directly through eval()<\/li>\n<li>Download and launch executable payloads<\/li>\n<li>Communicate through multiple beacon formats across rotating infrastructure<\/li>\n<\/ul>\n<p>This modular design allows the operator to change the final payload without rebuilding the entire infection chain. A system initially exposed to the same installer could later receive a stealer, loader, remote management tool, or another executable, making both detection and containment more difficult.<\/p>\n<h2>A Warning for Banks and Public Agencies<\/h2>\n<p>PhantomEnigma shows how attackers can turn trusted infrastructure into a detection advantage. A legitimate government domain, authenticated email, or clean file verdict may lower suspicion even when the infection chain is already active.<\/p>\n<p>For banks and public-sector organizations, the risk extends beyond one compromised endpoint. Stolen credentials and persistent backdoor access can expose internal systems, sensitive data, and financial operations, while fragmented alerts delay containment.<\/p>\n<p>Security teams should give employees a safe way to report suspicious official-looking messages and investigate them beyond the initial verdict. Catching the trusted lure early can prevent credential theft, additional payload delivery, and a wider operational incident.<\/p>\n<div class=\"article-board\">\n<p>Get PhantomEnigma IOCs, infrastructure findings, and detection guidance to strengthen threat hunting and response.<\/p>\n<p><a href=\"https:\/\/any.run\/cybersecurity-blog\/phantomenigma-research\/?utm_source=the+hacker+news&amp;utm_medium=article&amp;utm_campaign=hijacked+websites&amp;utm_content=blog&amp;utm_term=160726\" target=\"_blank\">Access Full Report<\/a><\/p>\n<\/div>\n<div class=\"cf note-b\">Found this article interesting? <span class=\"\">This article is a contributed piece from one of our valued partners.<\/span> Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ\" rel=\"noopener\" target=\"_blank\">Google News<\/a>, <a href=\"https:\/\/twitter.com\/thehackersnews\" rel=\"noopener\" target=\"_blank\">Twitter<\/a> and <a href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" rel=\"noopener\" target=\"_blank\">LinkedIn<\/a> to read more exclusive content we post.<\/div>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue804The Hacker News\ue802Jul 16, 2026Malware \/ Endpoint Security More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1832,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[220,2577,1163,385,804,1968],"class_list":["post-1831","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attack","tag-becamean","tag-channel","tag-government","tag-hijacked","tag-websites"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1831","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1831"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1831\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1832"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1831"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1831"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1831"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}