Connect with us

CyberSecurity

When the Government Gets Hacked: 20+ Official Sites Turned Into Malware Machines

Published

on

hijacked government websites

The Attack No One Saw Coming

You’d think a .gov.br domain would be the last place malware hides. Think again.

More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active campaign dubbed PhantomEnigma. The discovery came from ANY.RUN, a company known for interactive malware analysis and threat intelligence.

This isn’t a random defacement or a prank. These were official portals, weaponized to infect anyone who visited. The scale is alarming, but the technique is what makes it terrifying.

What Is PhantomEnigma?

PhantomEnigma isn’t a single piece of malware. It’s a coordinated operation with multiple attack arms, each designed to slip past traditional defenses.

ANY.RUN’s investigation uncovered previously undocumented backdoor behavior. That means even seasoned security teams hadn’t seen these tactics before. The campaign also revealed hidden infrastructure relationships—links between servers and domains that weren’t obvious until deep analysis.

Imagine a spider web. You see one strand, but the whole structure is connected. That’s how this campaign works.

The Backdoor That Wasn’t Supposed to Exist

Backdoors are common in malware, but this one operates differently. It hides its traces, communicates with command-and-control servers in unusual ways, and persists on infected systems longer than typical threats.

ANY.RUN’s sandbox environment allowed researchers to detonate the malware safely and watch its every move. What they found was a backdoor that could evade signature-based detection—the kind most antivirus tools rely on.

How Government Sites Became Attack Channels

The hijacking wasn’t a brute-force smash-and-grab. It involved compromising the websites’ underlying infrastructure, likely through stolen credentials or unpatched vulnerabilities.

Once in, the attackers injected malicious scripts that redirected visitors to exploit kits or directly downloaded payloads. The sites kept functioning normally—or so it seemed. Users saw no warning signs.

This is the classic supply-chain attack pattern: compromise a trusted source, then let the victims come to you.

Here’s what makes it worse:

  • Trust exploitation: Users assume .gov.br is safe. Attackers bank on that assumption.
  • Scale: 20+ sites means a wide net. Any Brazilian citizen or visitor could be affected.
  • Stealth: No defacement, no ransom note. Silence is the weapon.

Who’s Behind PhantomEnigma?

ANY.RUN hasn’t publicly attributed the campaign to a specific threat actor or nation-state. That’s not unusual—attribution takes months, sometimes years.

But the infrastructure relationships suggest a well-resourced operator. The multiple attack arms indicate modular development, meaning the group can swap out tools quickly.

For now, the focus is on mitigation, not blame.

What This Means for You

If you’re in Brazil, or you’ve visited any government site recently, you might be at risk. But even if you’re elsewhere, the lesson applies globally.

Government websites are no longer sacred ground. They’re prime targets because of their inherent trustworthiness.

Security experts recommend the following:

  1. Keep software updated—unpatched browsers and plugins are the easiest entry points.
  2. Use endpoint protection that includes behavioral analysis, not just signatures.
  3. Don’t rely on the URL alone—even .gov domains can be compromised.

For a deeper dive into how these attacks unfold, check out our analysis of malware delivery channels in recent campaigns. And if you’re curious about the tools used, we’ve covered backdoor analysis techniques that help uncover hidden threats.

The Bigger Picture

PhantomEnigma is a wake-up call. It shows that no website is too trusted to be weaponized.

ANY.RUN’s findings give defenders a fighting chance. By understanding the backdoor behavior and infrastructure links, security teams can hunt for similar indicators in their own networks.

The campaign is still active. That means more sites could be compromised, and more victims could fall.

Stay vigilant. Update your systems. And remember: even the most official-looking website can be a trap.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

CyberSecurity

Meta Names Assaf Keren as New CISO, Ending a 13-Year Era Under Guy Rosen

Published

on

Meta CISO Assaf Keren

A New Security Chief for the Social Media Giant

Assaf Keren is taking over as the Chief Information Security Officer of Meta, the company confirmed on Wednesday. He steps into a role that has been vacant since Guy Rosen, Meta’s first CISO, announced his retirement in June after a 13-year run with the company.

Keren’s appointment lands at a pivotal moment. Meta is pouring resources into frontier AI development, and the company’s security posture is being tested on a scale few other organizations can comprehend. Billions of users, one platform, and an attack surface that keeps growing.

From PayPal to Qualtrics to Meta

Keren doesn’t come to Meta without baggage — the good kind. His last stop was Qualtrics, where he served as SVP and Chief Security Officer. He joined the experience management software firm in March 2024, but his roots run deeper in the payments world.

Before Qualtrics, Keren spent nine years at PayPal, climbing through a wide range of leadership roles that eventually landed him in the CISO chair. That mix of payments security and enterprise software experience gives him a rare vantage point — he’s seen both the compliance-heavy world of financial services and the faster-moving enterprise SaaS space.

Why This Hire Matters for AI Security

Keren’s own words hint at where his priorities lie. In a statement announcing the move, he framed the challenge around AI trust infrastructure:

“Building AI at the frontier means building the trust infrastructure for it at the same frontier, with the same seriousness, at a scale that touches billions of people. There are few places in the world where that problem is bigger, harder, or more consequential.”

He added that the role combines everything he’s worked on throughout his career — security, systems, and the human side of earning confidence. That last part matters. Security leadership at Meta isn’t just about firewalls and threat intel; it’s about maintaining user trust in an environment where every misstep becomes front-page news.

The Guy Rosen Legacy

Rosen leaves big shoes to fill. He was appointed Meta’s first CISO in 2022, but his history with the company goes back much further. For years, he led product security and integrity efforts, helping Meta navigate everything from election interference to content moderation crises.

His retirement marks the end of an era. Rosen hasn’t confirmed any plans to join another company, though he’s indicated he’ll stay active as an advisor to leaders and organizations. That’s a loss for Meta’s internal bench, but a gain for the broader security community.

What Security Leaders Can Learn From This Transition

Meta’s CISO handoff offers a few lessons for security teams everywhere:

  • Succession planning pays off. Rosen’s departure was announced in June, giving Meta months to find the right replacement rather than scrambling.
  • Cross-industry experience is valuable. Keren’s path through payments and SaaS — not just social media — brings a broader threat model perspective.
  • AI security is becoming a CISO-level issue. Keren’s focus on AI trust infrastructure signals where the industry is heading.

For those keeping tabs on the broader cybersecurity leadership landscape, this appointment is one of several recent moves worth watching. The industry has seen a wave of high-profile CISO transitions lately, and each one reshapes the competitive dynamics at the top.

The Road Ahead for Meta’s Security Team

Keren inherits a security organization that’s both mature and under constant pressure. Meta operates at a scale where even small vulnerabilities can have outsized impact, and the regulatory environment around data protection and AI is only getting stricter.

His background suggests he’ll take a systems-oriented approach — thinking about security not as a series of isolated controls but as an integrated layer across Meta’s products. That’s exactly the mindset needed for the AI era, where model security, data governance, and application security are increasingly intertwined.

One open question: how will Keren shape Meta’s approach to external security research and disclosure? Rosen was known for maintaining a robust bug bounty program and strong ties with the researcher community. Early signs suggest Keren values that kind of collaboration, but only time will tell if he changes the playbook.

For now, the appointment is official. Keren is in. Rosen is out. And Meta’s security team has a new leader at a moment when the stakes have never been higher.

For more on recent moves in the industry, check out our coverage of other CISO appointments and security leadership changes. You can also follow the latest in enterprise security news and hiring announcements.

Continue Reading

CyberSecurity

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

Published

on

ClickLock macOS stealer

Meet ClickLock: A Stealer That Won’t Take No for an Answer

Imagine trying to work on your Mac, and every app you open closes itself within a fraction of a second. That’s the nightmare ClickLock inflicts on victims who refuse to hand over their login password.

This new ClickLock macOS stealer doesn’t just steal files silently. It uses a brutal, almost theatrical approach: kill every app in sight, over and over, until the user types their password into a fake system dialog. The malware even sets a precise 210-millisecond timer between kills — fast enough to make the Mac virtually unusable.

Security researchers at SentinelOne first documented the threat, noting how it targets macOS users with a surprisingly simple yet effective social engineering trick.

How the Attack Unfolds

The infection starts not with a malicious app, but with a command. Victims are tricked into pasting a script into Terminal — a common tactic in social engineering campaigns. The script immediately presents a fake system dialog asking for the user’s password.

If the user complies, the stealer grabs the credentials and likely exfiltrates them. But if the user clicks cancel? That’s when the punishment begins.

The 210ms Kill Loop

ClickLock installs two LaunchAgents — persistence mechanisms that ensure it runs at every login. Then it quietly exits. On the next login, the malware springs to life. Finder, Dock, Spotlight, Terminal, Activity Monitor — every essential app gets killed in a continuous loop.

The 210ms interval is key. It’s fast enough to prevent the user from opening a single app, yet slow enough to feel deliberate. The message is clear: type your password, or your Mac becomes a brick.

Why This Malware Is Different

Most infostealers operate silently, hoping to avoid detection. ClickLock takes the opposite approach. It draws attention to itself, using denial-of-service as leverage.

This is a psychological attack as much as a technical one. The victim isn’t just losing data — they’re losing control of their machine in real time. The pressure to give in and type the password becomes almost irresistible.

Researchers note that the fake dialog is designed to look exactly like macOS’s native password prompt. Even savvy users might hesitate before recognizing it as a phishing attempt.

How to Protect Yourself from ClickLock

Defending against this threat requires a combination of caution and technical hygiene. Here’s what you can do:

  • Never paste unknown commands into Terminal. If a website, email, or message asks you to run a script, treat it as a red flag.
  • Check for LaunchAgents. Look in ~/Library/LaunchAgents and /Library/LaunchAgents for unfamiliar plist files. ClickLock installs two of them.
  • Keep your Mac updated. Apple regularly patches security flaws, so running the latest macOS version helps.
  • Use a reputable antivirus tool. SentinelOne and other security suites can detect and block known stealer signatures.
  • Enable FileVault. Full-disk encryption adds a layer of protection even if credentials are compromised.

What to Do If You’re Already Infected

If your Mac starts killing apps after login, don’t panic. Boot into Safe Mode (hold Shift during startup), which prevents LaunchAgents from running. Then remove the malicious plist files and delete the source script. A malware scanner can help clean up any remnants.

After removal, change your Apple ID password and enable two-factor authentication. The attacker may have already captured credentials, so assume the worst and secure your accounts.

The Bigger Picture: macOS Malware Is Getting More Aggressive

ClickLock is part of a troubling trend. macOS malware has traditionally been less common than Windows threats, but that’s changing. Attackers are increasingly targeting Mac users with sophisticated social engineering and aggressive tactics.

This stealer’s approach — using app-killing as coercion — shows how far attackers will go to obtain a single password. It’s a reminder that the human element is often the weakest link in cybersecurity.

For more on protecting your digital life, check out our guide on macOS security best practices and learn how to spot phishing attempts on Mac.

Stay vigilant, and remember: no legitimate system dialog will ever ask you to paste a command into Terminal. If something feels off, it probably is.

Continue Reading

CyberSecurity

TELEPUZ Malware Hits the Scene: ClickFix Lures Deliver Modular Data-Stealing Threat

Published

on

TELEPUZ malware

Meet TELEPUZ: A New Modular Threat on the Block

Cybersecurity researchers have flagged a fresh modular malware strain called TELEPUZ that’s been riding the coattails of ClickFix lures on compromised websites since late April 2026. It’s not the flashiest name, but the threat is real — and it’s designed to do serious damage.

Elastic Security Labs researcher Cyril François broke down the findings in a technical report, describing TELEPUZ as “full-featured, lightweight, and modular.” That’s a dangerous combo. It means the malware packs a punch without being bloated, and its modular design lets attackers swap in new capabilities on the fly.

Here’s the kicker: while the number of command-and-control (C2) domains is currently small, the daily evolution of the infrastructure suggests this thing is scaling up fast. Early days, but the trajectory is worrying.

How ClickFix Lures Work: The Entry Point

ClickFix isn’t new, but it’s become a favorite social engineering trick. Attackers inject fake error prompts or CAPTCHA-style popups into compromised websites. When a visitor clicks, they’re instructed to copy a malicious payload and paste it into a terminal or PowerShell window. Boom — the malware gets a foothold.

In TELEPUZ’s case, the lures are embedded in sites that have already been hacked. The user thinks they’re solving a CAPTCHA or fixing a browser error. Instead, they’re executing a command that downloads the malware straight onto their machine.

It’s a low-friction attack. No phishing email, no malicious attachment — just a convincing popup on a site the victim already trusts.

What TELEPUZ Does Once It’s In

TELEPUZ isn’t a one-trick pony. According to François’s analysis, the malware is built to do two main things: steal data and run remote commands. But the modular architecture means those are just the starting points.

Data Theft Capabilities

The malware is designed to harvest sensitive information from infected systems. That could include credentials, browser cookies, or other valuable data. The lightweight design means it can run quietly in the background without drawing too much attention.

Remote Command Execution

Beyond theft, TELEPUZ can execute commands sent from its C2 servers. This gives attackers a direct line into the infected machine, letting them move laterally, drop additional payloads, or wreak havoc in real time.

The modular nature is what makes this particularly sneaky. Attackers can add new modules as the campaign evolves, meaning the threat landscape could shift quickly.

Infrastructure: Small Now, Growing Fast

François noted that the C2 infrastructure is currently limited to a small number of domains. But that’s not a reason to breathe easy. The daily changes in infrastructure signal active development and expansion.

This is a campaign that’s still in its early innings. Security teams should expect the C2 count to grow, and the attack methods to evolve as the operators refine their playbook.

Protecting Yourself Against ClickFix and TELEPUZ

So what can you do? The attack vector relies on social engineering, so awareness is your first line of defense.

  • Think before you click: If a website asks you to copy-paste a command into your terminal or PowerShell, stop. Legitimate sites don’t do that.
  • Keep your browser updated: Many ClickFix lures exploit browser vulnerabilities. Patching those closes the door.
  • Use endpoint detection tools: Security solutions that monitor for unusual command execution can catch TELEPUZ before it takes hold.
  • Verify site integrity: If a trusted site suddenly shows odd popups, it might be compromised. Leave and report it.

For security teams, the takeaway is to stay vigilant. The modular malware trend is growing, and TELEPUZ is the latest example. Monitoring C2 domains and watching for ClickFix lures on your users’ frequently visited sites can help you stay ahead.

The Bottom Line on TELEPUZ

TELEPUZ is a reminder that cyber threats keep getting more sophisticated. It’s lightweight, modular, and spreading through a social engineering trick that’s hard to spot. The small C2 footprint today could be a full-blown botnet tomorrow.

Stay sharp out there. And next time a website tells you to paste a command into your terminal — just say no.

Continue Reading

Trending