Brazil: PhantomEnigma and Banana RAT target banks
PhantomEnigma abuses .gov.br sites and trusted email to spread malware in Brazil. Banana RAT is also stealing banking credentials.
More than 20 Brazilian government websites were hijacked to serve malware in the PhantomEnigma campaign, according to reports circulated by ANY.RUN and republished by specialized media. In parallel, Trend Micro researchers exposed Banana RAT, a banking trojan identified as SHADOW-WATER-063, with fileless execution through PowerShell and functions for manipulating banking sessions.
PhantomEnigma uses Brazilian government domains
More than 20 Brazilian government websites were hijacked and turned into malware distribution channels in the PhantomEnigma campaign uncovered by ANY.RUN. The finding was echoed by The Hacker News and summarized by AllSec.sh and Pendergrass Consulting, which place it within a broader pattern of government domain abuse across more than 20 countries.
In the Brazilian case, the cited sources say the campaign targets banking organizations and public agencies. HackRead added that PhantomEnigma abuses Brazilian government domains and trusted email channels to go after banks specifically, using .gov.br links and what it describes as trusted email to bypass security controls. So far, the sources reviewed do not attribute the operation to APT groups or state-backed actors.
Banana RAT and banking session theft
Separately, Igor Urraza's technical blog reports that Trend Micro researchers disclosed the full operation of a banking trojan called Banana RAT, identified as SHADOW-WATER-063. The malware uses fileless execution through PowerShell, layered obfuscation techniques, and remote control capabilities to steal credentials and manipulate banking sessions.
Those capabilities include tampering with payments through Pix QR codes, a feature especially relevant to Brazil's financial ecosystem. According to Urraza's technical summary, Banana RAT appears designed to enable financial fraud aimed at Brazilian banks, although the text does not name specific institutions or confirm any identified victims.
The overlap between a campaign that reuses .gov.br infrastructure to deliver malware and a banking trojan focused on sessions and Pix payments points to wider pressure on Brazil's financial sector and public sphere, but the available sources still offer no consolidated public attribution for either PhantomEnigma or Banana RAT.
Sources
- Infraestructura gubernamental comprometida: ANY.RUN descubre campaña PhantomEnigmaq2bstudio.com· Q2BStudio
- Entrada de blog técnica sobre Banana RAT / SHADOW-WATER-063blog.iurlek.com· Igor Urraza
- Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malwareng.headtopics.com· Headtopics (resumen de ANY.RUN)
- 20+ Hijacked Government Websites Became an Attack Channelallsec.sh· AllSec.sh / The Hacker News
- PhantomEnigma Infects Organizations with Malware via Hijacked Government Websiteshackread.com· HackRead
- Hijacked Websites: When Trusted Sites Turn Dangerouspendergrassconsulting.com· Pendergrass Consulting



