Government security PhantomEnigma campaign hijacks Brazilian government websites for malware delivery July 17, 2026 Share By SC Staff (Adobe Stock) More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign discovered by ANY.RUN, according to The Hacker News. The PhantomEnigma campaign has evolved, shifting from banking-focused attacks in 2025 to leveraging compromised .gov.br websites and authenticated emails in 2026. This strategy allows attackers to use trusted government infrastructure as a lure, bypassing initial security checks. The campaign begins with fake police-themed documents or digital power of attorney notices, some containing QR codes or links to lookalike government resources. Emails are often sent through compromised mailboxes, passing SPF, DKIM, and DMARC authentication, enhancing their legitimacy. Victims are then redirected through compromised government hosts or police-themed domains to a malicious installer. This installer deploys a modular Inno/Node.js backdoor, often hidden within patched legitimate applications like Electron or Boostnote. The backdoor collects system information, establishes persistence, and communicates with rotating command-and-control infrastructure. It can execute JavaScript and download additional payloads, including stealers, loaders, and remote management tools. This modularity makes detection and containment difficult, posing a significant risk to banks and public agencies by enabling credential compromise, unauthorized access, fraud, and data exposure. Source: The Hacker News SC Staff Related Government security Declassified documents detail China’s analysis of U.S. voter data SC Staff July 17, 2026 The declassified records offer greater detail on Chinese intelligence collection involving U.S. voter data and highlight internal debates within the intelligence community regarding the characterization of Beijing's election-related activities. Government security Arizona launches second regional security operations center to boost cyber defense SC Staff July 14, 2026 The Central Regional Security Operations Center, operating from Glendale Community College and Paradise Valley Community College, functions as a student-run cyber defense hub. Critical Infrastructure Security Russia’s FSB attacks critical infrastructure, says 12 Western nations Steve Zurier July 13, 2026 Russian hackers target outdated Cisco routers in decade-long espionage campaign. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds