Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

PhantomEnigma

153
Global rank
113 infographic chevron month
Month rank
203 infographic chevron week
Week rank

PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.

Backdoor
Type
LATAM
Origin
1 March, 2025
First seen
24 September, 2026
Last seen

How to analyze PhantomEnigma with ANY.RUN

Type
LATAM
Origin
1 March, 2025
First seen
24 September, 2026
Last seen

IOCs

IP addresses
2.17.197.90
66.22.76.213
48.209.138.189
128.24.231.64
199.232.210.172
2.17.197.122
74.178.240.51
150.171.109.193
150.171.109.194
150.171.109.105
188.114.96.3
150.171.28.11
150.171.27.11
20.190.159.75
2.23.246.9
48.209.138.168
2.23.246.101
104.18.22.222
52.123.243.194
23.194.190.165
Hashes
6671fe83b7a07c8932ee89164d1f2793b2318058eb8b98dc5c06ee0a5a3b0ec1
0223497a0b8b033aa58a3a521b8629869386cf7ab0e2f101963d328aa62193f7
1f74d5e9292979b573ebd59741d46cb93ff391acdd083d340b94370753d92437
e15c5b469ea3e0a695bea6f2c82bcf8e62821074939ddd85b77e0007ff165475
81765af2daef323061dcbc5e61fc16481cb74b3bac9ad8a174b186523586f6c5
d3825a70337940ebbd0a5c072984e13245920cdf8898bd225c8d27a6dfc9cb53
8d5f2fa83e103cf08b57eaa67521df9194f45cbdbcb37da52ad586097a14d106
a4c3d2b9c7bb3fd8d1441c31bd4ee71a595d66b44fcf49ddb310252320169989
e9ddcaa4189fddd25ed97fc8c789eca7b6ca16390b2392ae3276f0c8e1aa4619
a53d0741798b287c6dd7afa64aee473f305e65d3f49463bb9d7408ec3b12bf5f
5154e165bd6c2cc0cfbcd8916498c7abab0497923bafcd5cb07673fe8480087d
8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903
a853c2ffec17057872340eee242ae4d96cbf2b520ae27d903e1b2fef1a5f9d1c
b47f1a8a744ecdc7a3da35804f88552805d33f51a726b87a2105acdfae406b07
f573f5d21d5d8a054aad1ffcbe0165391a4d93a5aa3e23c3db0752759adfd50c
5638e11ae0ffa26607545afc060cc603083863acb1f7c723547d6dc1d3ff29c9
c5d08a8c4e5afc8b48d965c309d3b98930592da304cf04ac265c8b24ea3d6891
294fd58816e5105234628d99af3c64bcc105826171da32ea8134649d9592613b
f1c788423c7a7792319168ce5c5c871918b7f6f428c7304e511692702bf260d9
96df2e47e94b1f37801782cf0dd19fad59f84df05842c0af24223928d4ae2be5
Domains
edge.microsoft.com
ocsp.digicert.com
static.edge.microsoftapp.net
settings-win.data.microsoft.com
www.microsoft.com
edge-consumer-static.azureedge.net
go.microsoft.com
activation-v2.sls.microsoft.com
nexusrules.officeapps.live.com
www.bing.com
update.googleapis.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
edge-mobile-static.azureedge.net
login.live.com
copilot.microsoft.com
prodoc.ap.gov.br
ecs.office.com
self.events.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
api.edgeoffer.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:s3viv-fqp1qnwzr_rltk-bdyc0qyayy82iak9igbfv0&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://prodoc.ap.gov.br/plugins/
https://prodoc.ap.gov.br/18f5227b-e27b-445a-a53f-f845fbe69b40/stormcaster.js
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://prodoc.ap.gov.br/favicon.ico
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://prodoc.ap.gov.br/c99a4269-161c-4242-a3f0-28d44fa6ce24?
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d279%2526e%253d1
https://update.googleapis.com/service/update2/json?cup2key=14:xhtedn_oc6rwzgc_hxpmy2pjqajmpwad2qqxtpbqkbe&cup2hreq=55af25cd7a40c14522f80db77dbee0f673e7e8b01a5efcebd9b72460f2279b5e
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
Last Seen at

Recent blog posts

post image
Threat Coverage Digest: New Malware Reports a...
watchers 5278
comments 0
post image
Phishing Response Protocol: 3 Essential SOC S...
watchers 7461
comments 0
post image
Major Cyber Attacks in September 2026: US and...
watchers 11406
comments 0

Key Takeaways

  • Abuse of Trusted Government Systems: According to ANY.RUN, PhantomEnigma utilizes at least 20 hijacked .gov.br municipal and police portals to distribute malware. This allows phishing emails to pass standard authentication checks and reach victims with a high level of perceived trust.
  • Durable Build-Chain Fingerprints: While C2 domains and IP addresses rotate weekly, the operation relies on a consistent Delphi-compiled Inno Setup installer carrying an embedded Node.js or Electron application. This build-chain combination allows for 100% recall across analyzed clusters.
  • Coordinated Multi-Arm Operation: The campaign includes the "Ofício-PC" quishing (QR-code phishing) arm, which uses fake police PDF documents to trigger PowerShell commands. Shared infrastructure between this arm and the Node.js backdoor arm confirms they belong to the same operator.
  • High Business and Financial Risk: The operation specifically targets banking credentials (notably Banco do Brasil) and installs Remote Monitoring and Management (RMM) tools like Syncro, PDQ Connect, and MeshAgent to maintain persistent access to corporate infrastructure.

A compromised PhantomEnigma website delivering malware A compromised PhantomEnigma website delivering malware

What is PhantomEnigma?

PhantomEnigma is a mature, Brazil-focused crimeware operation that provides a turnkey solution for financial fraud and infrastructure expansion. It operates as a coordinated campaign that combines modular malware, frequently rotated infrastructure, and the exploitation of trusted government hosting to evade traditional security perimeters.

Read extended analysis of PhantomEnigma attacks on ANY.RUN’s Cybersecurity blog

The operation has significantly evolved in technical complexity. Originally documented in 2025 as a browser-extension banker (Generation A), it has transitioned into a sophisticated modular Node.js backdoor (Generation B). A core tactic involves patching legitimate applications, such as the Boostnote note-taking app, and injecting a malicious index.js file into the Electron runtime. This allows the malware to masquerade as legitimate software while performing reconnaissance and executing remote tasks.

A timeline of PhantomEnigma attacks A timeline of PhantomEnigma attacks

PhantomEnigma pursues two distinct attack paths:

  • Individual Targets: Stealing authentication tokens and credentials for Brazilian online banking systems to facilitate direct financial theft.
  • Organizational Targets: Expanding attacker infrastructure by compromising corporate email servers and installing RMM agents to establish a persistent foothold for future operations.

The operation's resilience is built into its decoupled architecture, where the delivery channel (government portals), command-and-control (C2) servers, and exfiltration endpoints are managed as separate layers. This structure ensures that the malware can continue to function even if individual components are identified and blocked.

How PhantomEnigma Threatens Businesses and Organizations

For organizations, PhantomEnigma represents a sophisticated threat that extends far beyond simple banking fraud. By infiltrating corporate environments, the group creates a foundation for long-term persistence and large-scale exploitation:

  • Financial Fraud and Data Theft: The primary objective is the theft of credentials for Brazilian banking institutions, such as Banco do Brasil. Compromised credentials enable unauthorized transactions, payment redirection, and the exposure of sensitive financial records.
  • Persistent Infrastructure Control: Attacks on organizations often involve the deployment of Remote Monitoring and Management (RMM) tools, including Syncro RMM, PDQ Connect, and MeshAgent. These tools allow attackers to maintain a permanent foothold, bypass standard security alerts, and expand their reach within the victim's infrastructure.
  • Evasion and Delayed Containment: One of the greatest risks is the operation's high success rate in evading automated detection. Nearly one-third of analyzed activity initially received "clean" verdicts because the malware utilizes trusted government domains and modular, delayed payloads. This "visibility gap" delays investigation and gives the operation more time to spread undetected.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

The targeting profile of PhantomEnigma is heavily specialized, with a clear focus on the financial and public sectors within a specific geographic region:

Brazil remains the strongest targeting signal, representing 60.3% of the .gov.br delivery cluster and 46% of the operator C2 cohort observed in ANY.RUN data.

The group’s primary goal is the compromise of users at Brazilian banks. This includes both individual account holders and employees of financial institutions whose corporate systems are targeted to facilitate larger fraud operations.

While municipal and police portals in Brazil are the most frequent delivery channels, they are often the compromised middleman rather than the final victim. At least 20 different government portals have been identified as hosting malicious payloads.

Activity has been observed targeting consulting firms, logistics companies, retail, chemical, and IT sectors. The common denominator is often the use of legitimate corporate email servers to host phishing lures, exploiting the existing trust between business partners.

How Does PhantomEnigma Malware Function? (The Sandbox Analysis)

Detonating a PhantomEnigma sample in the ANY.RUN Interactive Sandbox provides a transparent, step-by-step look at how this modular crimeware operation functions.

View analysis of a PhantomEnigma attack inside ANY.RUN’s Interactive Sandbox

By moving beyond static analysis, defenders can observe the following stages of the attack in real-time:

Stage 1: The Initial Lure and Trusted Hosting

The infection chain begins with a spoofed email, often appearing as an official "Polícia Civil" summons or a "Procuração Digital" (Digital Power of Attorney) notary notice. To bypass email security filters, the link provided in the email leads to a compromised Brazilian government host (.gov.br) or a police-themed typosquat .com domain.

A fake email sent as part of a PhantomEnigma campaign A fake email sent as part of a PhantomEnigma campaign

Stage 2: The Delphi/Inno Setup Installer

Upon clicking the link, the host serves a Delphi-compiled Inno Setup installer, such as Procuracao_Digital.exe. When executed in the sandbox, this installer silently unpacks a patched Electron/Node.js-based application, often masquerading as the legitimate note-taking app Boostnote.

A compromised PhantomEnigma website delivering malware A compromised PhantomEnigma website delivering malware

Stage 3: Backdoor Activation and Masquerading

The malicious logic is contained within a file named index.js hidden inside the application's resources. As the Electron host loads this script, the sandbox reveals several critical behaviors:

  • Self-Deobfuscation: The script reverses multiple layers of obfuscation to reveal its command-and-control (C2) logic.
  • Reconnaissance: The malware uses child_process to gather system information, including the computer name, username, and machine ID.
  • Masquerading: The decoy binary (originally Boost Note.exe) is often renamed to generic titles like Grape.exe or placed in installation directories with "word-salad" names such as ProSoftxUltraToolator to avoid detection.

PhantomEnigma backdoor code PhantomEnigma backdoor code

Stage 4: Real-Time Beaconing and C2 Communication

ANY.RUN analysts have identified at least two parallel beacon generations used by the backdoor:

  • Generation 1: Uses a GET request to a /laravel.php endpoint, with victim data encoded in the URL parameters.
  • Generation 2: Uses a POST request to an /nbw/ endpoint with a JSON-formatted body containing the machine ID and campaign tags. The backdoor is programmed to check for new commands from the C2 server every 180 seconds.
Stage 5: Modular Second-Stage Delivery

Once a connection is established, the server can return tasks for the infected machine to execute:

  • In-Process Execution: The server sends JavaScript code that the backdoor runs directly using the eval() function.
  • Child Process Deployment: The C2 can transmit separate executable files to be dropped and launched. This modularity allows the attacker to deliver the final payload, such as a stealer, loader, or Remote Monitoring and Management (RMM) tool like Syncro or MeshAgent.
Stage 6: Persistence and Infrastructure Rotation

To ensure a long-term foothold, the malware establishes persistence through Registry Run keys or the setLoginItemSettings function. Analysts can observe that while the malware's code remains a durable fingerprint, the C2 infrastructure rotates weekly, moving between different Cloudflare-fronted domains and compromised government portals to stay ahead of static blocklists.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against PhantomEnigma

Because PhantomEnigma rotates its command-and-control (C2) infrastructure weekly and utilizes compromised legitimate government portals, static blocklists often fail to provide adequate protection. To counter this, security teams can leverage ANY.RUN’s Threat Intelligence to identify the underlying "build-chain" fingerprints that remain stable even as domains change.

Threat Intelligence Lookup allows analysts to pivot from a single suspicious file to the entire cluster of related activity by searching for the malware's technical DNA rather than just its current address.

TI Lookup displays the latest threat intel on PhantomEnigma attacks TI Lookup displays the latest threat intel on PhantomEnigma attacks

Security teams can identify related activity by searching for specific build-chain tags: domainName:”.gov.br” AND threatName:”nodejs” AND threatName:”inno*”.

This way, SOC teams can track the latest changes in PhantomEnigma’s campaigns and always have actionable intel to enrich and update their defenses.

TI Feeds deliver fresh IOCs to your SIEM/SOAR for proactive threat blocking TI Feeds deliver fresh IOCs to your SIEM/SOAR for proactive threat blocking

For organizations looking to automate their proactive defense, ANY.RUN’s Threat Intelligence Feeds provide a real-time stream of validated indicators based on the latest sandbox investigations by 15K SOCs and 600K analysts. The feeds deliver the most recent C2 domains, IP addresses, and URLs, directly into SIEM, SOAR, and EDR platforms. By integrating these feeds, teams can block emerging malicious infrastructure.

ANY.RUN’s TI Report on PhantomEnigma reveals all domains used by attackers ANY.RUN’s TI Report on PhantomEnigma reveals all domains used by attackers

ANY.RUN also published a dedicated Threat Intelligence (TI) Report on the PhantomEnigma operation. The report presents a deep-dive investigation by ANY.RUN’s dedicated team of TI experts who meticulously track active attacks on businesses. The TI Report provides curated TTPs (Tactics, Techniques, and Procedures) and IOCs, offering security leaders a "playbook" for proactive defense.

By combining the behavioral visibility of the Interactive Sandbox with Threat Intelligence, businesses can effectively track the evolution of PhantomEnigma and secure their infrastructure against trust-based evasion tactics.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

PhantomEnigma represents a growing trend of "trust-based" evasion, where attackers bypass traditional security perimeters by hiding behind compromised government infrastructure and legitimate corporate email accounts. The operation remains difficult to track because its infrastructure rotates faster than its code. Reducing business risk requires a transition to behavioral identity analytics and proactive threat hunting that connects fragmented indicators.

Frequently Asked Questions: PhantomEnigma

1. What is PhantomEnigma?

PhantomEnigma is a sophisticated crimeware operation targeting Brazilian banking organizations and the public sector. It primarily utilizes a modular Node.js backdoor to steal credentials and maintain persistent access to corporate cloud environments.

2. How does PhantomEnigma evade email security?

The group hijacks legitimate .gov.br municipal and police portals to host its malware. Because the delivery comes from trusted government infrastructure, phishing emails often pass SPF, DKIM, and DMARC checks, reaching victims with a high level of perceived legitimacy.

3. What are the key technical indicators of a PhantomEnigma infection?

The most reliable signal is the build chain: a Delphi-compiled Inno Setup installer that silently deploys a patched Electron application (often masquerading as Boostnote). Technically, the malware is identified by network beacons to /laravel.php or /nbw/ endpoints.

4. Why do many PhantomEnigma samples receive "clean" verdicts?

Attackers use modular, delayed payloads and trusted infrastructure to appear benign to automated scanners. Many versions also perform reconnaissance and check for specific banking plugins (like Warsaw Technology) before activating their malicious logic.

5. How can organizations mitigate this threat?

To mitigate this threat, companies need to integrate interactive sandboxing and proactive threat intelligence to expose the modular logic of malware that often evades traditional automated scanners. By using solutions like TI Lookup and TI Feeds, organizations can identify stable build-chain fingerprints and block rotating infrastructure in real-time. Furthermore, leveraging expert-led TI Reports allows security teams to connect fragmented indicators and significantly shorten the time required for threat containment.

HAVE A LOOK AT

Havoc screenshot
Havoc
havoc
Havoc is an advanced post-exploitation framework used by hackers to take control of a system once they've breached it. With Havoc, attackers can run commands remotely, inject malicious processes, and access sensitive data. It's often used in targeted attacks, allowing cybercriminals to stay hidden in a network while stealing information or launching further attacks. Its flexibility and ability to bypass detection make it a serious threat, especially in environments that rely on traditional security tools.
Read More
Oyster screenshot
Oyster
oyster
Oyster (also seen in reporting as Broomstick or CleanUpLoader) is a Windows backdoor/loader actively used in multi-stage intrusion campaigns. Recent campaigns weaponize SEO-poisoning and malvertising to trick IT and dev users into downloading trojanized installers (PuTTY, WinSCP, Microsoft Teams, etc.), which then drop Oyster to establish a persistent foothold and load additional payloads (often leading to data theft or ransomware).
Read More
LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
Quasar RAT screenshot
Quasar RAT
quasar trojan rat
Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More
SnappyClient screenshot
SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.
Read More