Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Brazilian financial institutions and public agencies
Incident: Hijacking of over 20 Brazilian government websites to serve as malware delivery channels.
Impact: Unauthorized access to internal systems and potential theft of sensitive financial and government data.
Attacker: PhantomEnigma
Analysis: The threat actor PhantomEnigma has pivoted to using hijacked government infrastructure to bypass email security and establish trust with targets. The operation utilizes compromised mailboxes that pass SPF and DKIM checks to deliver fake police-themed documents. Once clicked, victims are routed through legitimate government hosts to a modular Node.js backdoor capable of executing arbitrary JavaScript.
Recommendations: Implement strict monitoring for unusual outbound redirects from trusted government domains.; Train staff to verify official communications via secondary channels, regardless of the sender’s domain authenticity.; Enhance endpoint detection to identify and block modular Inno/Node.js-based backdoor signatures.
Source: The Hacker News / ANY.RUN
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source