New Browser Threat: Operation Phantom Enigma Targets Brazilian Users with Malicious Extensions!
Operation Phantom Enigma is targeting Brazilian users with phishing emails masquerading as invoices. These emails unleash a malicious extension for Chromium-based browsers, siphoning authentication data like a digital vacuum cleaner. With 722 downloads across several countries, this campaign is as sneaky as a ninja at a sleepover.

Hot Take:
It’s official: Brazilian users are the latest addition to the “Let’s See Who Can Hack Us First” club. With the rise of Operation Phantom Enigma, it seems like our friends in Brazil, along with a few other countries, have been involuntarily signed up for a master class in phishing and data theft. Maybe it’s time to start using smoke signals instead of emails?
Key Points:
- Operation Phantom Enigma targets Chromium-based browsers with a malicious extension.
- Phishing emails impersonate invoices to trick users into downloading harmful attachments.
- The attack spans multiple countries, hitting 70 unique companies and 722 downloads.
- Malware disables security controls, establishes persistence, and communicates with remote servers.
- Malicious browser extensions have been removed, but attackers employ alternate installation methods.
Already a member? Log in here