Government websites used as an attack channel: PhantomEnigma masks a malicious chain behind trusted infrastructure

Colleagues, I’d like to draw your attention to a cybersecurity case: more than 20 Brazilian government websites were used as malware delivery channels.
ANY.RUN researchers linked PhantomEnigma activity to phishing emails that looked like official police documents. In some cases, the messages passed SPF, DKIM, and DMARC checks, which increased trust.
Victims were then redirected via compromised .gov.br resources or lookalike domains, and the payload launched an installer and a modular backdoor.
Why it matters: trusted infrastructure reduces suspicion, while a modular design makes detection and blocking harder.
In your view, are companies ready to validate such emails not only by links, but by the full delivery chain?
#cybersecurity #phishing #malware #ThreatHunting

