216.73.216.226

Operation Phantom Enigma

· Published 05/06/2025 16:53 · Modified 05/06/2025 17:46

Export JSON

Essential information

Published
05/06/2025 16:53
Modified
05/06/2025 17:46
Tags
2025-06-05 banking browser extension mesh agent pdq connect agent phishing powershell stealer
Related entities
2 techniques (mitre), 6 others

Description

A malicious campaign targeting primarily Brazilian residents has been discovered, with attacks detected since early 2025. The attackers employed emails, some sent from compromised company servers, to distribute malware. Two attack chains were identified: one using a malicious for Google Chrome, Microsoft Edge, and Brave, and another utilizing or . The campaign aimed to steal authentication data from victims' bank accounts, particularly targeting Banco do Brasil customers. Over 700 downloads of the malicious extension were recorded, affecting users in Brazil, Colombia, Czech Republic, Mexico, Russia, Vietnam, and other countries. The attackers used sophisticated techniques, including virtualization checks, UAC bypass, and file deletion to evade detection.

External references