20+ Hijacked Government Websites Became an Attack Channel 18%

By The Hacker News36%

7/16/2026, 4:58:00 AM

BS Summary: This article contains 20 faulty reasoning types, including Pessimism Bias, Framing Effect, and Availability Heuristic, with Negativity Bias as the most egregious example at 9.6% saturation with 76 hits. Analysis detected 676 faulty-reasoning hits from 790 analyzed words, generating a BS Score of 33.2% and a BS Rank of 18% (18,029 of 21,887 articles). This article is better (less manipulative) than 82.40% of the article peer group.

More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. 
The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign putting banks and public agencies at risk. 
By connecting hundreds of seemingly unrelated sandbox sessions, ANY.RUN researchers exposed the operation’s broader scope and showed how trusted .gov.br links and authenticated emails helped the activity remain hidden. 
For the complete technical analysis, infrastructure details, indicators, and detection guidance, read the full PhantomEnigma investigation report 
Trusted Government Infrastructure Became the Lure 
The attack began with fake police-themed documents presented as official “Ofício Polícia Civil” or “Procuração Digital” notices. 
Some contained QR codes, while others directed recipients to links designed to look like legitimate government resources. 
In several cases, the emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks. 
That gave the messages a stronger appearance of legitimacy than ordinary spoofed phishing emails. 
Victims were then redirected through compromised .gov.br hosts or police-themed lookalike domains before reaching the malicious installer. 
The government systems were used as trusted delivery infrastructure, not necessarily as the final targets of the campaign. 
Observed Government Hosts 
Among the compromised systems observed during the investigation were timon.ma.gov[.]br, loginam.sesp.es.gov[.]br (state public security), aplicacao.cbm.mt.gov[.]br (fire department), prodoc.ap.gov[.]br, and others. 
These legitimate municipal, public-security, and judicial portals were used at different stages of the delivery chain. 
Several also appeared across more than one PhantomEnigma attack arm, helping researchers connect activity that initially looked unrelated. 
PhantomEnigma’s Evolution: Two Paths to Harder Detection 
Timeline of PhantomEnigma’s malisious activity 
The timeline shows one operation evolving along two main paths: 
Delivery: PhantomEnigma moved from banking-focused activity in 2025 to abusing compromised .gov.br websites and email accounts in 2026. 
This gave the campaign a more trusted route to victims without confirming a new target group. 
Arsenal: The malware evolved from a browser-extension banker into a modular Inno/Node.js backdoor capable of executing JavaScript and delivering additional payloads. 
For security teams, this combination creates a serious visibility gap. 
Trusted infrastructure reduces suspicion, modular payloads can change after infection, and rotating C2 domains quickly make static blocklists outdated. 
Behavioral analysis and continuous threat hunting provide more reliable coverage as the campaign evolves. 
From Trusted Email to Full Compromise: The PhantomEnigma Attack Chain 
The analysis process of PhantomEnigma inside interactive sandbox 
Once a victim engaged with the lure, the campaign moved through a multi-stage infection chain: 
Phishing email: A fake police-themed or official-document lure reaches the victim. 
Trusted infrastructure: The link redirects through a compromised government host or police-themed lookalike domain. 
Malicious installer: An Inno Setup, MSI, or another installer starts the infection. 
Patched Electron application: Legitimate software loads a malicious index.js backdoor. 
Backdoor activation: The malware collects system data, establishes persistence, and connects to rotating C2 infrastructure. 
Second-stage delivery: The backdoor executes JavaScript or delivers stealers, loaders, RMM software, and other malware. 
Business impact: The infection can lead to credential compromise, unauthorized access, fraud, data exposure, and operational disruption. 
What Researchers Found Inside PhantomEnigma’s Backdoor 
The sandbox sessions exposed more than a simple downloader. 
Hidden inside a patched Boostnote and other applications was a modular index.js backdoor built to identify infected machines, maintain access, and deliver different payloads on demand. 
Once activated, the backdoor could: 
Collect the victim’s computer name, username, and system details 
Create a persistent machine ID and read a campaign tag stored beside the installer 
Establish persistence through login settings 
Check for new commands every 180 seconds 
Execute JavaScript directly through eval() 
Download and launch executable payloads 
Communicate through multiple beacon formats across rotating infrastructure 
This modular design allows the operator to change the final payload without rebuilding the entire infection chain. 
A system initially exposed to the same installer could later receive a stealer, loader, remote management tool, or another executable, making both detection and containment more difficult. 
A Warning for Banks and Public Agencies 
PhantomEnigma shows how attackers can turn trusted infrastructure into a detection advantage. 
A legitimate government domain, authenticated email, or clean file verdict may lower suspicion even when the infection chain is already active. 
For banks and public-sector organizations, the risk extends beyond one compromised endpoint. 
Stolen credentials and persistent backdoor access can expose internal systems, sensitive data, and financial operations, while fragmented alerts delay containment. 
Security teams should give employees a safe way to report suspicious official-looking messages and investigate them beyond the initial verdict. 
Catching the trusted lure early can prevent credential theft, additional payload delivery, and a wider operational incident. 
Get PhantomEnigma IOCs, infrastructure findings, and detection guidance to strengthen threat hunting and response. 
Access Full Report 
Article reasoning-pattern comparisonThis article: 5.9%The Hacker News: 1.8%The Hacker News: 1.9%Confirmation Bias5.9%This article: 0.0%The Hacker News: 0.8%The Hacker News: 1.2%Anchoring Bias0.0%This article: 6.2%The Hacker News: 3.5%The Hacker News: 3.3%Availability Heuristic6.2%This article: 1.8%The Hacker News: 1.5%The Hacker News: 1.5%Representativeness Heuristic1.8%This article: 3.9%The Hacker News: 0.3%The Hacker News: 0.6%Hindsight Bias3.9%This article: 0.0%The Hacker News: 2.7%The Hacker News: 2.5%Overconfidence Bias0.0%This article: 6.3%The Hacker News: 2.8%The Hacker News: 2.7%Framing Effect6.3%This article: 2.7%The Hacker News: 1.3%The Hacker News: 1.0%Loss Aversion2.7%This article: 0.0%The Hacker News: 0.6%The Hacker News: 0.6%Status Quo Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 3.9%The Hacker News: 1.4%The Hacker News: 1.3%Optimism Bias3.9%This article: 7.1%The Hacker News: 1.4%The Hacker News: 1.6%Pessimism Bias7.1%This article: 9.6%The Hacker News: 6.6%The Hacker News: 6.7%Negativity Bias9.6%This article: 0.0%The Hacker News: 1.5%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 5.4%The Hacker News: 0.3%The Hacker News: 0.4%Fundamental Attribution Error5.4%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 3.3%The Hacker News: 0.8%The Hacker News: 0.6%Halo Effect3.3%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 2.3%The Hacker News: 1.0%The Hacker News: 1.5%Recency Bias2.3%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%The Hacker News: 0.2%The Hacker News: 0.1%Straw Man0.0%This article: 4.9%The Hacker News: 3.7%The Hacker News: 4.0%Appeal to Authority4.9%This article: 1.3%The Hacker News: 2.4%The Hacker News: 1.6%False Dilemma1.3%This article: 1.3%The Hacker News: 0.4%The Hacker News: 0.5%Slippery Slope1.3%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 0.0%The Hacker News: 5.1%The Hacker News: 4.3%Hasty Generalization0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.2%Bandwagon0.0%This article: 0.0%The Hacker News: 1.3%The Hacker News: 1.1%Appeal to Emotion0.0%This article: 0.0%The Hacker News: 0.9%The Hacker News: 0.5%Begging the Question0.0%This article: 5.9%The Hacker News: 1.8%The Hacker News: 1.9%Post Hoc (False Cause)5.9%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%The Hacker News: 0.4%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%The Hacker News: 0.2%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%The Hacker News: 0.5%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%The Hacker News: 1.2%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 2.7%The Hacker News: 1.3%The Hacker News: 2.3%Ambiguity (Equivocation)2.7%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 0.0%The Hacker News: 0.8%The Hacker News: 1.4%Unattributed Quote0.0%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 4.2%The Hacker News: 1.9%The Hacker News: 2.3%Biased Writer Voice4.2%This article: 2.5%The Hacker News: 5.0%The Hacker News: 4.4%Indoctrination2.5%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 4.3%The Hacker News: 6.7%The Hacker News: 3.0%Attempt to Sell a Product or S…4.3%

790 words analyzed.

Speakers

1speaker3.7%attributed speech761writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 8 words • 0.0% coverageWriter's voice • 33 words • 100.0% coverageWriter's voice • 24 words • 0.0% coverageANY.RUN • 29 words • 0.0% coverageWriter's voice • 17 words • 100.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 20 words • 100.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 14 words • 100.0% coverageWriter's voice • 3 words • 100.0% coverage
Selected voice

ANY.RUN

100%flagged-word coverage
29 attributed words100% of attributed speech64% writer coverage
0%2.5%5.0%Attempt to Sell a Product -4.5 ptsWriter: 4.5%ANY.RUN: 0.0%0.0%Biased Writer Voice-4.3 ptsWriter: 4.3%ANY.RUN: 0.0%0.0%Indoctrination-2.6 ptsWriter: 2.6%ANY.RUN: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.