Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

PhantomEnigma

162
Global rank
139 infographic chevron month
Month rank
197 infographic chevron week
Week rank
0
IOCs

PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.

Backdoor
Type
LATAM
Origin
1 March, 2025
First seen
4 August, 2026
Last seen

How to analyze PhantomEnigma with ANY.RUN

Type
LATAM
Origin
1 March, 2025
First seen
4 August, 2026
Last seen

IOCs

IP addresses
20.42.65.88
74.178.76.128
20.190.160.2
2.22.122.8
150.171.27.11
150.171.22.17
40.126.31.73
135.234.160.244
177.52.182.44
95.100.102.101
150.171.28.11
172.211.123.248
150.171.109.193
48.209.133.15
199.232.214.172
34.160.81.0
23.216.77.6
2.22.251.15
104.18.22.222
135.233.95.135
Hashes
435a6722c786b0a56fbe7387028f1d9d3f3a2d0fb615bb8fee118727c3f59b7b
48da2f39e100d4085767e94966b43f4fa95ff6a0698fba57ed460914e35f94a0
74502372f3e457ae4d05546c47b4fd88c8df6ed8eb6166b6feb8bec1798ec6dc
80626386e94017e8950ab75791da258c1165867e49187ebf8c9f77b3e1da4478
8bd46b4c9a2058faa4144f29ffefeed4ee32cafd6d7b5347a91c499ea52893f3
59ab5bfd6c6d4f124269d7419fde08368ac3462e2fb17d2f707d8816ff9764c0
6652830c2607c722b66f1b57de15877ab8fc5dca406cc5b335afeb365d0f32c1
55986972f5f3c9446f876c576e1cd30fd4f04cd26527efbb5ad834637c740e4c
9b75aece458d05e13a299afdd745de6ae6069287862e1d5bc718facb24da7692
a0a259ddf5f5b786f51dfc6b8302aea8e8820e03ec7ab7be87f96cccd17efb4c
0776eca71f280f369a20f6edbd03c192b1722dfe6a0681c40d63798bb81a6459
5ad1ce1860079ccf25a7fe62211361fe6cd2ac06a9fc4616a288fa3bb6ffa648
5e3e30991733d8c977afb5cef564a855c2bccd96c080d83e5422e3876cd512fd
124f2039c547d2a4fe83b9a56e6c3b911d383289d47238f4f558ea4061c4348e
c7e03fbb9bc1528ea1681c2433ad73d241b023c6200a7b13fa63ec083b81e017
d60b69794e2094b2aef35abbed5d17b9e14b41a4fef2ad5a38da4e2171d1c49f
4c8e75fd14416c2d8a461682a5d67157efe0c637969ddd8aeb563733a836b62f
6bc095689e62eb2aa401033b090870d24373aa4e992089c2256773133c994969
89dbdb1542343cb549ecd12cd8c79ae01e6111215445ea6b091f337faddd6ebe
f1f923f068e89fca8e8d52b3706185cace306455dc1babd24a9a7328757c0b53
Domains
static.edge.microsoftapp.net
mehigneuhe.com
nexusrules.officeapps.live.com
crl.microsoft.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
client.wns.windows.com
browser.events.data.microsoft.com
copilot.microsoft.com
login.live.com
o4508134825000960.ingest.us.sentry.io
www.bing.com
ocsp.globalsign.com
api.edgeoffer.microsoft.com
update.googleapis.com
settings-win.data.microsoft.com
edge.microsoft.com
google.com
go.microsoft.com
config.edge.skype.com
aefd.nelreports.net
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:utonhcdx0lkogbm7ewgoxtbkr24mf1j5__ymh2ylwfo&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://camaraparaguacu.sp.gov.br/doc/dcuxkm/s7q88t
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d228%2526e%253d1
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://update.googleapis.com/service/update2/json?cup2key=14:39qovnzxq-inwn8avffxj4qe7icz_prj8qv37i9n2eg&cup2hreq=87d0c83591d5a735d76d54919028c1ad9557a2469acb814cb24b3813fb3630b6
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://clients2.googleusercontent.com/crx/blobs/auu14h9lifl_xdfovyc6ev9d9ia6qcy2fpggd1uevuk_yoqwcsmd13fexvuvu2cn93z41_hou8y7vuivvhjkvqkxhviwy8eqaszi6uvsh8cwzz02zvegbus0d2hnwvroeqeaxlka5cc_zznn-sn4gcvn46um6ojs-psr/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_108_1_0.crx
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://login.live.com/rst2.srf
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
Last Seen at

Recent blog posts

post image
North Korean IT Workers Scheme: Detection IOC...
watchers 5932
comments 0
post image
Hunt Malware & Phishing Threats with ANY....
watchers 5801
comments 0
post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 18764
comments 0

Key Takeaways

  • Abuse of Trusted Government Systems: According to ANY.RUN, PhantomEnigma utilizes at least 20 hijacked .gov.br municipal and police portals to distribute malware. This allows phishing emails to pass standard authentication checks and reach victims with a high level of perceived trust.
  • Durable Build-Chain Fingerprints: While C2 domains and IP addresses rotate weekly, the operation relies on a consistent Delphi-compiled Inno Setup installer carrying an embedded Node.js or Electron application. This build-chain combination allows for 100% recall across analyzed clusters.
  • Coordinated Multi-Arm Operation: The campaign includes the "Ofício-PC" quishing (QR-code phishing) arm, which uses fake police PDF documents to trigger PowerShell commands. Shared infrastructure between this arm and the Node.js backdoor arm confirms they belong to the same operator.
  • High Business and Financial Risk: The operation specifically targets banking credentials (notably Banco do Brasil) and installs Remote Monitoring and Management (RMM) tools like Syncro, PDQ Connect, and MeshAgent to maintain persistent access to corporate infrastructure.

A compromised PhantomEnigma website delivering malware A compromised PhantomEnigma website delivering malware

What is PhantomEnigma?

PhantomEnigma is a mature, Brazil-focused crimeware operation that provides a turnkey solution for financial fraud and infrastructure expansion. It operates as a coordinated campaign that combines modular malware, frequently rotated infrastructure, and the exploitation of trusted government hosting to evade traditional security perimeters.

Read extended analysis of PhantomEnigma attacks on ANY.RUN’s Cybersecurity blog

The operation has significantly evolved in technical complexity. Originally documented in 2025 as a browser-extension banker (Generation A), it has transitioned into a sophisticated modular Node.js backdoor (Generation B). A core tactic involves patching legitimate applications, such as the Boostnote note-taking app, and injecting a malicious index.js file into the Electron runtime. This allows the malware to masquerade as legitimate software while performing reconnaissance and executing remote tasks.

A timeline of PhantomEnigma attacks A timeline of PhantomEnigma attacks

PhantomEnigma pursues two distinct attack paths:

  • Individual Targets: Stealing authentication tokens and credentials for Brazilian online banking systems to facilitate direct financial theft.
  • Organizational Targets: Expanding attacker infrastructure by compromising corporate email servers and installing RMM agents to establish a persistent foothold for future operations.

The operation's resilience is built into its decoupled architecture, where the delivery channel (government portals), command-and-control (C2) servers, and exfiltration endpoints are managed as separate layers. This structure ensures that the malware can continue to function even if individual components are identified and blocked.

How PhantomEnigma Threatens Businesses and Organizations

For organizations, PhantomEnigma represents a sophisticated threat that extends far beyond simple banking fraud. By infiltrating corporate environments, the group creates a foundation for long-term persistence and large-scale exploitation:

  • Financial Fraud and Data Theft: The primary objective is the theft of credentials for Brazilian banking institutions, such as Banco do Brasil. Compromised credentials enable unauthorized transactions, payment redirection, and the exposure of sensitive financial records.
  • Persistent Infrastructure Control: Attacks on organizations often involve the deployment of Remote Monitoring and Management (RMM) tools, including Syncro RMM, PDQ Connect, and MeshAgent. These tools allow attackers to maintain a permanent foothold, bypass standard security alerts, and expand their reach within the victim's infrastructure.
  • Evasion and Delayed Containment: One of the greatest risks is the operation's high success rate in evading automated detection. Nearly one-third of analyzed activity initially received "clean" verdicts because the malware utilizes trusted government domains and modular, delayed payloads. This "visibility gap" delays investigation and gives the operation more time to spread undetected.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

The targeting profile of PhantomEnigma is heavily specialized, with a clear focus on the financial and public sectors within a specific geographic region:

Brazil remains the strongest targeting signal, representing 60.3% of the .gov.br delivery cluster and 46% of the operator C2 cohort observed in ANY.RUN data.

The group’s primary goal is the compromise of users at Brazilian banks. This includes both individual account holders and employees of financial institutions whose corporate systems are targeted to facilitate larger fraud operations.

While municipal and police portals in Brazil are the most frequent delivery channels, they are often the compromised middleman rather than the final victim. At least 20 different government portals have been identified as hosting malicious payloads.

Activity has been observed targeting consulting firms, logistics companies, retail, chemical, and IT sectors. The common denominator is often the use of legitimate corporate email servers to host phishing lures, exploiting the existing trust between business partners.

How Does PhantomEnigma Malware Function? (The Sandbox Analysis)

Detonating a PhantomEnigma sample in the ANY.RUN Interactive Sandbox provides a transparent, step-by-step look at how this modular crimeware operation functions.

View analysis of a PhantomEnigma attack inside ANY.RUN’s Interactive Sandbox

By moving beyond static analysis, defenders can observe the following stages of the attack in real-time:

Stage 1: The Initial Lure and Trusted Hosting

The infection chain begins with a spoofed email, often appearing as an official "Polícia Civil" summons or a "Procuração Digital" (Digital Power of Attorney) notary notice. To bypass email security filters, the link provided in the email leads to a compromised Brazilian government host (.gov.br) or a police-themed typosquat .com domain.

A fake email sent as part of a PhantomEnigma campaign A fake email sent as part of a PhantomEnigma campaign

Stage 2: The Delphi/Inno Setup Installer

Upon clicking the link, the host serves a Delphi-compiled Inno Setup installer, such as Procuracao_Digital.exe. When executed in the sandbox, this installer silently unpacks a patched Electron/Node.js-based application, often masquerading as the legitimate note-taking app Boostnote.

A compromised PhantomEnigma website delivering malware A compromised PhantomEnigma website delivering malware

Stage 3: Backdoor Activation and Masquerading

The malicious logic is contained within a file named index.js hidden inside the application's resources. As the Electron host loads this script, the sandbox reveals several critical behaviors:

  • Self-Deobfuscation: The script reverses multiple layers of obfuscation to reveal its command-and-control (C2) logic.
  • Reconnaissance: The malware uses child_process to gather system information, including the computer name, username, and machine ID.
  • Masquerading: The decoy binary (originally Boost Note.exe) is often renamed to generic titles like Grape.exe or placed in installation directories with "word-salad" names such as ProSoftxUltraToolator to avoid detection.

PhantomEnigma backdoor code PhantomEnigma backdoor code

Stage 4: Real-Time Beaconing and C2 Communication

ANY.RUN analysts have identified at least two parallel beacon generations used by the backdoor:

  • Generation 1: Uses a GET request to a /laravel.php endpoint, with victim data encoded in the URL parameters.
  • Generation 2: Uses a POST request to an /nbw/ endpoint with a JSON-formatted body containing the machine ID and campaign tags. The backdoor is programmed to check for new commands from the C2 server every 180 seconds.
Stage 5: Modular Second-Stage Delivery

Once a connection is established, the server can return tasks for the infected machine to execute:

  • In-Process Execution: The server sends JavaScript code that the backdoor runs directly using the eval() function.
  • Child Process Deployment: The C2 can transmit separate executable files to be dropped and launched. This modularity allows the attacker to deliver the final payload, such as a stealer, loader, or Remote Monitoring and Management (RMM) tool like Syncro or MeshAgent.
Stage 6: Persistence and Infrastructure Rotation

To ensure a long-term foothold, the malware establishes persistence through Registry Run keys or the setLoginItemSettings function. Analysts can observe that while the malware's code remains a durable fingerprint, the C2 infrastructure rotates weekly, moving between different Cloudflare-fronted domains and compromised government portals to stay ahead of static blocklists.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against PhantomEnigma

Because PhantomEnigma rotates its command-and-control (C2) infrastructure weekly and utilizes compromised legitimate government portals, static blocklists often fail to provide adequate protection. To counter this, security teams can leverage ANY.RUN’s Threat Intelligence to identify the underlying "build-chain" fingerprints that remain stable even as domains change.

Threat Intelligence Lookup allows analysts to pivot from a single suspicious file to the entire cluster of related activity by searching for the malware's technical DNA rather than just its current address.

TI Lookup displays the latest threat intel on PhantomEnigma attacks TI Lookup displays the latest threat intel on PhantomEnigma attacks

Security teams can identify related activity by searching for specific build-chain tags: domainName:”.gov.br” AND threatName:”nodejs” AND threatName:”inno*”.

This way, SOC teams can track the latest changes in PhantomEnigma’s campaigns and always have actionable intel to enrich and update their defenses.

TI Feeds deliver fresh IOCs to your SIEM/SOAR for proactive threat blocking TI Feeds deliver fresh IOCs to your SIEM/SOAR for proactive threat blocking

For organizations looking to automate their proactive defense, ANY.RUN’s Threat Intelligence Feeds provide a real-time stream of validated indicators based on the latest sandbox investigations by 15K SOCs and 600K analysts. The feeds deliver the most recent C2 domains, IP addresses, and URLs, directly into SIEM, SOAR, and EDR platforms. By integrating these feeds, teams can block emerging malicious infrastructure.

ANY.RUN’s TI Report on PhantomEnigma reveals all domains used by attackers ANY.RUN’s TI Report on PhantomEnigma reveals all domains used by attackers

ANY.RUN also published a dedicated Threat Intelligence (TI) Report on the PhantomEnigma operation. The report presents a deep-dive investigation by ANY.RUN’s dedicated team of TI experts who meticulously track active attacks on businesses. The TI Report provides curated TTPs (Tactics, Techniques, and Procedures) and IOCs, offering security leaders a "playbook" for proactive defense.

By combining the behavioral visibility of the Interactive Sandbox with Threat Intelligence, businesses can effectively track the evolution of PhantomEnigma and secure their infrastructure against trust-based evasion tactics.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

PhantomEnigma represents a growing trend of "trust-based" evasion, where attackers bypass traditional security perimeters by hiding behind compromised government infrastructure and legitimate corporate email accounts. The operation remains difficult to track because its infrastructure rotates faster than its code. Reducing business risk requires a transition to behavioral identity analytics and proactive threat hunting that connects fragmented indicators.

Frequently Asked Questions: PhantomEnigma

1. What is PhantomEnigma?

PhantomEnigma is a sophisticated crimeware operation targeting Brazilian banking organizations and the public sector. It primarily utilizes a modular Node.js backdoor to steal credentials and maintain persistent access to corporate cloud environments.

2. How does PhantomEnigma evade email security?

The group hijacks legitimate .gov.br municipal and police portals to host its malware. Because the delivery comes from trusted government infrastructure, phishing emails often pass SPF, DKIM, and DMARC checks, reaching victims with a high level of perceived legitimacy.

3. What are the key technical indicators of a PhantomEnigma infection?

The most reliable signal is the build chain: a Delphi-compiled Inno Setup installer that silently deploys a patched Electron application (often masquerading as Boostnote). Technically, the malware is identified by network beacons to /laravel.php or /nbw/ endpoints.

4. Why do many PhantomEnigma samples receive "clean" verdicts?

Attackers use modular, delayed payloads and trusted infrastructure to appear benign to automated scanners. Many versions also perform reconnaissance and check for specific banking plugins (like Warsaw Technology) before activating their malicious logic.

5. How can organizations mitigate this threat?

To mitigate this threat, companies need to integrate interactive sandboxing and proactive threat intelligence to expose the modular logic of malware that often evades traditional automated scanners. By using solutions like TI Lookup and TI Feeds, organizations can identify stable build-chain fingerprints and block rotating infrastructure in real-time. Furthermore, leveraging expert-led TI Reports allows security teams to connect fragmented indicators and significantly shorten the time required for threat containment.

HAVE A LOOK AT

Roning Loader screenshot
Roning Loader
roning
RoningLoader is a multi-stage Windows loader designed to operate quietly while preparing systems for deeper compromise. It abuses trusted system tools and interferes with security controls to reduce the chances of early detection. Instead of acting as a final payload, it creates conditions for follow-on malware to execute more effectively. Its use of staged execution and code injection allows attackers to blend into legitimate activity and escalate impact. This makes early behavioral detection critical before the attack chain progresses further.
Read More
INC Ransomware screenshot
INC Ransomware is a ransomware-as-a-service (RaaS) spotted in mid-2023. It targets industries like retail, real estate, finance, healthcare, and education, primarily in the U.S. and UK. It encrypts and exfiltrates data demanding a ransom. It employs advanced evasion techniques, destroys backup, and abuses legitimate system tools at all the stages of the kill chain.
Read More
XRed screenshot
XRed
xred
XRed operates as a stealthy backdoor, enabling cybercriminals to gain unauthorized remote access to infected systems. XRed has gained particular notoriety for its distribution through trojanized legitimate software and hardware drivers, making it exceptionally dangerous due to its ability to masquerade as trusted applications.
Read More
Quasar RAT screenshot
Quasar RAT
quasar trojan rat
Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.
Read More
MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
Cactus Ransomware screenshot
Cactus ransomware-as-a-service (RaaS) was first caught in March 2023 targeting corporate networks. It became known for its self-encrypting payload and double extortion tactics. Cactus primarily targets large enterprises across industries in finance, manufacturing, IT, and healthcare. It is known for using custom encryption techniques, remote access tools, and penetration testing frameworks to maximize damage.
Read More