Multiple Brazilian Government Websites Get Hijacked and Used as Malware

Recently, over twenty Brazilian government sites have been turned into malware delivery mediums via a PhantomEnigma campaign. The attacks started with police-themed phishing documents and emails that redirected victims to malware installers. The PhantomEnigma operation has also evolved in multiple ways to evade detection, targeting .gov websites and employing more sophisticated backdoor methods. The entire process uses several trusted domain lookalikes and activates backdoors before the victim has any idea as to what is happening, and upon activation, the target machine's sensitive credentials, login settings, and code execution vulnerabilities are all exploited.