Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

PhantomEnigma

150
Global rank
130 infographic chevron month
Month rank
74 infographic chevron week
Week rank
0
IOCs

PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.

Backdoor
Type
LATAM
Origin
1 March, 2025
First seen
8 September, 2026
Last seen

How to analyze PhantomEnigma with ANY.RUN

Type
LATAM
Origin
1 March, 2025
First seen
8 September, 2026
Last seen

IOCs

IP addresses
172.211.123.250
57.153.246.3
74.179.77.204
48.192.1.65
150.171.109.106
95.100.102.101
48.209.133.15
150.171.109.194
52.102.113.39
2.19.13.249
128.201.75.205
2.16.241.205
150.171.27.11
172.211.123.248
2.18.244.224
150.171.109.99
20.190.159.68
150.171.109.100
23.10.249.82
150.171.22.17
Hashes
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
3a657eddec2905ce29950e37a3cc78c6839afc858fe26a89490a1502be032d13
c4b07931b3fc37bc80d56a367783e7fa7c04ced4befec7f57ed079c38c960400
ccbb779363f7f2b5174e25ebb1bba5dd9b72c4e08c9f8d64751e95ed3db85571
14bf8af0ec00ec4d1b1c48ed250d95f1917a05b4480866a0f0d3e6575f2fb0ba
04bec01401dc633a4e305486256cb72fb9eaa3accb6e80f26a093aea17ee4c48
34f3d13e671204edd7c8324b40eb7070919c6c67e0e9aaf5d2f8bad5fab09ca7
fbeb1790218a24ac41e8c2e5bfa278508a345cef2e67be7fc2ddd9464ce8a4b2
4e987457f6e0b88119955bff45499d74bc9102631e01e3cad4b9fdcaed4d2f2e
ae0140c26ae95539091f4d4ed9bf99bfe871f02f71d5526d0e156d20b7f18a01
49a6af676b2133a16df0825aa3efa29c4e60d3e0399003ab86ec8a8147273f8a
6ee966926c812be209a7f0db5b7fa51877af46fe02eca2a104b3c498f7a4cb36
39264c00acb42118f46af4f8d088566ec6ef0b7e7dd9cf016336e1a0b1c631ea
59db6fd8d1d9bad9e73f0afbfb3a029ef27a8617074bfeb5f25ff8054078572b
04e5fa94cad76062bb4be8dd15dc3938ff14bc5e04a836e3f6e8bdaacf7e0e9d
ea718425a21da6a90f8e9af98fad5f875ea518a1549fb568a62b9683391d8e9b
c01e639c938fec3f7f831427ce59fa784f16668e651a4cd6bdb13e4ff547dedf
90e734b891a5cf67004cd19fb56718b84d70fc0b758d207bc2c2e6b520e2f19a
Domains
xpaywalletcdn.azureedge.net
go.microsoft.com
google.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
login.live.com
fe3cr.delivery.mp.microsoft.com
crl.microsoft.com
edge-cloud-resource-static.azureedge.net
static.edge.microsoftapp.net
www.bing.com
copilot.microsoft.com
nam10.safelinks.protection.outlook.com
marapoama.sp.gov.br
slscr.update.microsoft.com
client.wns.windows.com
settings-win.data.microsoft.com
config.edge.skype.com
activation-v2.sls.microsoft.com
api.edgeoffer.microsoft.com
edge.microsoft.com
URLs
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://nam10.safelinks.protection.outlook.com/?url=https%3a%2f%2fmarapoama.sp.gov.br%2fdocumentoikzc0rcxz&data=05%7c02%7cjose.neto%40zema.com%7c4f46f46516c941c3ab2c08df0d9ec893%7cb484723419164c52a75bb6def04b43a7%7c0%7c0%7c639244647780133770%7cunknown%7ctwfpbgzsb3d8eyjfbxb0eu1hcgkionrydwusilyioiiwljaumdawmcisilaioijxaw4zmiisikfoijoitwfpbcisilduijoyfq%3d%3d%7c4000%7c%7c%7c&sdata=oqthmthwho%2bwhmme7hfqfpbkjssjsrwaudr3ns%2bqj6w%3d&reserved=0
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:ldmnjwcqfilczw3kochkswntxoirl30pw_7teudbtwm&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://marapoama.sp.gov.br/documentoikzc0rcxz
https://marapoama.sp.gov.br/brasao.png
https://marapoama.sp.gov.br/qr.png
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://marapoama.sp.gov.br/favicon.ico
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d263%2526e%253d1
https://update.googleapis.com/service/update2/json?cup2key=14:wnwlfgnyjbuue-iad-vdyrdrzpvqnf61in41trez_qy&cup2hreq=e09e65df04e210550c26a4dd6e02da6afd4638774635ccad839c8aa1cce82e1b
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 3836
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 8068
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 10163
comments 0

Key Takeaways

  • Abuse of Trusted Government Systems: According to ANY.RUN, PhantomEnigma utilizes at least 20 hijacked .gov.br municipal and police portals to distribute malware. This allows phishing emails to pass standard authentication checks and reach victims with a high level of perceived trust.
  • Durable Build-Chain Fingerprints: While C2 domains and IP addresses rotate weekly, the operation relies on a consistent Delphi-compiled Inno Setup installer carrying an embedded Node.js or Electron application. This build-chain combination allows for 100% recall across analyzed clusters.
  • Coordinated Multi-Arm Operation: The campaign includes the "Ofício-PC" quishing (QR-code phishing) arm, which uses fake police PDF documents to trigger PowerShell commands. Shared infrastructure between this arm and the Node.js backdoor arm confirms they belong to the same operator.
  • High Business and Financial Risk: The operation specifically targets banking credentials (notably Banco do Brasil) and installs Remote Monitoring and Management (RMM) tools like Syncro, PDQ Connect, and MeshAgent to maintain persistent access to corporate infrastructure.

A compromised PhantomEnigma website delivering malware A compromised PhantomEnigma website delivering malware

What is PhantomEnigma?

PhantomEnigma is a mature, Brazil-focused crimeware operation that provides a turnkey solution for financial fraud and infrastructure expansion. It operates as a coordinated campaign that combines modular malware, frequently rotated infrastructure, and the exploitation of trusted government hosting to evade traditional security perimeters.

Read extended analysis of PhantomEnigma attacks on ANY.RUN’s Cybersecurity blog

The operation has significantly evolved in technical complexity. Originally documented in 2025 as a browser-extension banker (Generation A), it has transitioned into a sophisticated modular Node.js backdoor (Generation B). A core tactic involves patching legitimate applications, such as the Boostnote note-taking app, and injecting a malicious index.js file into the Electron runtime. This allows the malware to masquerade as legitimate software while performing reconnaissance and executing remote tasks.

A timeline of PhantomEnigma attacks A timeline of PhantomEnigma attacks

PhantomEnigma pursues two distinct attack paths:

  • Individual Targets: Stealing authentication tokens and credentials for Brazilian online banking systems to facilitate direct financial theft.
  • Organizational Targets: Expanding attacker infrastructure by compromising corporate email servers and installing RMM agents to establish a persistent foothold for future operations.

The operation's resilience is built into its decoupled architecture, where the delivery channel (government portals), command-and-control (C2) servers, and exfiltration endpoints are managed as separate layers. This structure ensures that the malware can continue to function even if individual components are identified and blocked.

How PhantomEnigma Threatens Businesses and Organizations

For organizations, PhantomEnigma represents a sophisticated threat that extends far beyond simple banking fraud. By infiltrating corporate environments, the group creates a foundation for long-term persistence and large-scale exploitation:

  • Financial Fraud and Data Theft: The primary objective is the theft of credentials for Brazilian banking institutions, such as Banco do Brasil. Compromised credentials enable unauthorized transactions, payment redirection, and the exposure of sensitive financial records.
  • Persistent Infrastructure Control: Attacks on organizations often involve the deployment of Remote Monitoring and Management (RMM) tools, including Syncro RMM, PDQ Connect, and MeshAgent. These tools allow attackers to maintain a permanent foothold, bypass standard security alerts, and expand their reach within the victim's infrastructure.
  • Evasion and Delayed Containment: One of the greatest risks is the operation's high success rate in evading automated detection. Nearly one-third of analyzed activity initially received "clean" verdicts because the malware utilizes trusted government domains and modular, delayed payloads. This "visibility gap" delays investigation and gives the operation more time to spread undetected.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

The targeting profile of PhantomEnigma is heavily specialized, with a clear focus on the financial and public sectors within a specific geographic region:

Brazil remains the strongest targeting signal, representing 60.3% of the .gov.br delivery cluster and 46% of the operator C2 cohort observed in ANY.RUN data.

The group’s primary goal is the compromise of users at Brazilian banks. This includes both individual account holders and employees of financial institutions whose corporate systems are targeted to facilitate larger fraud operations.

While municipal and police portals in Brazil are the most frequent delivery channels, they are often the compromised middleman rather than the final victim. At least 20 different government portals have been identified as hosting malicious payloads.

Activity has been observed targeting consulting firms, logistics companies, retail, chemical, and IT sectors. The common denominator is often the use of legitimate corporate email servers to host phishing lures, exploiting the existing trust between business partners.

How Does PhantomEnigma Malware Function? (The Sandbox Analysis)

Detonating a PhantomEnigma sample in the ANY.RUN Interactive Sandbox provides a transparent, step-by-step look at how this modular crimeware operation functions.

View analysis of a PhantomEnigma attack inside ANY.RUN’s Interactive Sandbox

By moving beyond static analysis, defenders can observe the following stages of the attack in real-time:

Stage 1: The Initial Lure and Trusted Hosting

The infection chain begins with a spoofed email, often appearing as an official "Polícia Civil" summons or a "Procuração Digital" (Digital Power of Attorney) notary notice. To bypass email security filters, the link provided in the email leads to a compromised Brazilian government host (.gov.br) or a police-themed typosquat .com domain.

A fake email sent as part of a PhantomEnigma campaign A fake email sent as part of a PhantomEnigma campaign

Stage 2: The Delphi/Inno Setup Installer

Upon clicking the link, the host serves a Delphi-compiled Inno Setup installer, such as Procuracao_Digital.exe. When executed in the sandbox, this installer silently unpacks a patched Electron/Node.js-based application, often masquerading as the legitimate note-taking app Boostnote.

A compromised PhantomEnigma website delivering malware A compromised PhantomEnigma website delivering malware

Stage 3: Backdoor Activation and Masquerading

The malicious logic is contained within a file named index.js hidden inside the application's resources. As the Electron host loads this script, the sandbox reveals several critical behaviors:

  • Self-Deobfuscation: The script reverses multiple layers of obfuscation to reveal its command-and-control (C2) logic.
  • Reconnaissance: The malware uses child_process to gather system information, including the computer name, username, and machine ID.
  • Masquerading: The decoy binary (originally Boost Note.exe) is often renamed to generic titles like Grape.exe or placed in installation directories with "word-salad" names such as ProSoftxUltraToolator to avoid detection.

PhantomEnigma backdoor code PhantomEnigma backdoor code

Stage 4: Real-Time Beaconing and C2 Communication

ANY.RUN analysts have identified at least two parallel beacon generations used by the backdoor:

  • Generation 1: Uses a GET request to a /laravel.php endpoint, with victim data encoded in the URL parameters.
  • Generation 2: Uses a POST request to an /nbw/ endpoint with a JSON-formatted body containing the machine ID and campaign tags. The backdoor is programmed to check for new commands from the C2 server every 180 seconds.
Stage 5: Modular Second-Stage Delivery

Once a connection is established, the server can return tasks for the infected machine to execute:

  • In-Process Execution: The server sends JavaScript code that the backdoor runs directly using the eval() function.
  • Child Process Deployment: The C2 can transmit separate executable files to be dropped and launched. This modularity allows the attacker to deliver the final payload, such as a stealer, loader, or Remote Monitoring and Management (RMM) tool like Syncro or MeshAgent.
Stage 6: Persistence and Infrastructure Rotation

To ensure a long-term foothold, the malware establishes persistence through Registry Run keys or the setLoginItemSettings function. Analysts can observe that while the malware's code remains a durable fingerprint, the C2 infrastructure rotates weekly, moving between different Cloudflare-fronted domains and compromised government portals to stay ahead of static blocklists.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against PhantomEnigma

Because PhantomEnigma rotates its command-and-control (C2) infrastructure weekly and utilizes compromised legitimate government portals, static blocklists often fail to provide adequate protection. To counter this, security teams can leverage ANY.RUN’s Threat Intelligence to identify the underlying "build-chain" fingerprints that remain stable even as domains change.

Threat Intelligence Lookup allows analysts to pivot from a single suspicious file to the entire cluster of related activity by searching for the malware's technical DNA rather than just its current address.

TI Lookup displays the latest threat intel on PhantomEnigma attacks TI Lookup displays the latest threat intel on PhantomEnigma attacks

Security teams can identify related activity by searching for specific build-chain tags: domainName:”.gov.br” AND threatName:”nodejs” AND threatName:”inno*”.

This way, SOC teams can track the latest changes in PhantomEnigma’s campaigns and always have actionable intel to enrich and update their defenses.

TI Feeds deliver fresh IOCs to your SIEM/SOAR for proactive threat blocking TI Feeds deliver fresh IOCs to your SIEM/SOAR for proactive threat blocking

For organizations looking to automate their proactive defense, ANY.RUN’s Threat Intelligence Feeds provide a real-time stream of validated indicators based on the latest sandbox investigations by 15K SOCs and 600K analysts. The feeds deliver the most recent C2 domains, IP addresses, and URLs, directly into SIEM, SOAR, and EDR platforms. By integrating these feeds, teams can block emerging malicious infrastructure.

ANY.RUN’s TI Report on PhantomEnigma reveals all domains used by attackers ANY.RUN’s TI Report on PhantomEnigma reveals all domains used by attackers

ANY.RUN also published a dedicated Threat Intelligence (TI) Report on the PhantomEnigma operation. The report presents a deep-dive investigation by ANY.RUN’s dedicated team of TI experts who meticulously track active attacks on businesses. The TI Report provides curated TTPs (Tactics, Techniques, and Procedures) and IOCs, offering security leaders a "playbook" for proactive defense.

By combining the behavioral visibility of the Interactive Sandbox with Threat Intelligence, businesses can effectively track the evolution of PhantomEnigma and secure their infrastructure against trust-based evasion tactics.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

PhantomEnigma represents a growing trend of "trust-based" evasion, where attackers bypass traditional security perimeters by hiding behind compromised government infrastructure and legitimate corporate email accounts. The operation remains difficult to track because its infrastructure rotates faster than its code. Reducing business risk requires a transition to behavioral identity analytics and proactive threat hunting that connects fragmented indicators.

Frequently Asked Questions: PhantomEnigma

1. What is PhantomEnigma?

PhantomEnigma is a sophisticated crimeware operation targeting Brazilian banking organizations and the public sector. It primarily utilizes a modular Node.js backdoor to steal credentials and maintain persistent access to corporate cloud environments.

2. How does PhantomEnigma evade email security?

The group hijacks legitimate .gov.br municipal and police portals to host its malware. Because the delivery comes from trusted government infrastructure, phishing emails often pass SPF, DKIM, and DMARC checks, reaching victims with a high level of perceived legitimacy.

3. What are the key technical indicators of a PhantomEnigma infection?

The most reliable signal is the build chain: a Delphi-compiled Inno Setup installer that silently deploys a patched Electron application (often masquerading as Boostnote). Technically, the malware is identified by network beacons to /laravel.php or /nbw/ endpoints.

4. Why do many PhantomEnigma samples receive "clean" verdicts?

Attackers use modular, delayed payloads and trusted infrastructure to appear benign to automated scanners. Many versions also perform reconnaissance and check for specific banking plugins (like Warsaw Technology) before activating their malicious logic.

5. How can organizations mitigate this threat?

To mitigate this threat, companies need to integrate interactive sandboxing and proactive threat intelligence to expose the modular logic of malware that often evades traditional automated scanners. By using solutions like TI Lookup and TI Feeds, organizations can identify stable build-chain fingerprints and block rotating infrastructure in real-time. Furthermore, leveraging expert-led TI Reports allows security teams to connect fragmented indicators and significantly shorten the time required for threat containment.

HAVE A LOOK AT

RedLine screenshot
RedLine
redline stealer redline stealer malware
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Read More
SalatStealer screenshot
SalatStealer
salatstealer
SalatStealer, also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.
Read More
Play Ransomware screenshot
Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.
Read More
Spyware screenshot
Spyware
spyware
Spyware is a stealth form of malware whose primary objective is to gather sensitive information, such as personal data, login credentials, and financial details, by monitoring user activities and exploiting system vulnerabilities. Spyware operates secretly in the background, evading detection while transmitting collected data to cybercriminals, who can then use it for malicious purposes like identity theft, financial fraud, or espionage.
Read More
Balada Injector screenshot
Balada Injector is a long-running malware campaign that targets WordPress websites by exploiting vulnerabilities in plugins and themes. The attackers inject malicious code into compromised sites, leading to unauthorized redirects, data theft, and the creation of [backdoors](https://any.run/malware-trends/backdoor) for persistent access. The campaign operates in waves, with spikes in activity observed every few weeks, continually adapting to exploit newly discovered vulnerabilities.
Read More
BlackMatter screenshot
BlackMatter
blackmatter
BlackMatter is a ransomware strain operating as a Ransomware-as-a-Service (RaaS), designed to encrypt files, remove recovery options, and extort victims across critical industries. Emerging in 2021, it quickly became a major concern due to its ability to evade defenses, spread across networks, and cause large-scale operational disruption, forcing security teams to act against a highly destructive and persistent threat.
Read More