> ## Content Index
> Fetch the complete content index at: https://blog.quimerax.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Meet Shadow Ledger: The Group That Hijacks Official Authority to Hit Brazil’s Financial Sector
- URL: https://blog.quimerax.com/meet-shadow-ledger-the-group-that-hijacks-official-authority-to-hit-brazils-financial-sector/
- Published: 2026-09-15T11:21:04.000Z
- Updated: 2026-09-15T12:11:26.000Z
- Author: QuimeraX Team

On February 19, 2026, Woovi’s name began circulating across social media and tech communities. The company, which operates in the payments and *Pix* ecosystem, had been linked to an incident. That same day, its CEO issued a statement: **the incident was believed to have started with an** ***email*** **sent from a government domain and a** ***PDF***, described at the time as part of the exploitation of a ***zero-day*** vulnerability.

At first glance, it looked like a sophisticated, isolated attack. The **QuimeraX** **Cyber Threat Intelligence** (*CTI*) team saw it differently.

The attack vector matched a *phishing* campaign that was already circulating against Brazil’s financial sector. The messages were being sent from genuinely compromised institutional infrastructure, without relying on traditional *spoofing*. The *PDF* prompted the victim to download what appeared to be a **“digital certificate.”** At the time, there was no technical evidence that a *zero-day* was being exploited.

**That public incident made the pattern visible. But it was not the beginning of the story.**

Throughout our monitoring, we identified the same pattern across **several other organizations** in the financial and services ecosystem. Payment institutions, *fintechs*, service providers, and adjacent organizations appeared in the same attack flow throughout 2026\. **We are not naming them here.** For defenders, understanding how the operation works matters more than knowing the full list of victims.

The *hunting* that followed, along with the monitoring we have maintained ever since, revealed an operation that was older, more persistent, and more industrialized than that single incident initially suggested. **At QuimeraX, we track this activity as a distinct cluster, which we call Shadow Ledger.**

## Why Shadow Ledger and Not PLUMP SPIDER?

![](https://blog.quimerax.com/content/images/2026/09/image-20.png)

During our monitoring of these campaigns, we identified analyses from other security teams linking part of this activity to **PLUMP SPIDER**, another Brazilian threat group known for targeting the financial sector.

**Our assessment is different.**

**QuimeraX** tracks **Shadow Ledger as a group distinct from PLUMP SPIDER**. This separation is not based solely on differences in *modus operandi*, infrastructure, or TTPs.

Throughout the investigation, **we correlated information about both operations that goes beyond purely technical analysis**. We have evidence, including non-public information about individuals involved in these groups' operations, that supports our assessment that they are distinct threat actors.

For operational reasons, we will not disclose identities, sources, or other details in this post that could expose the investigation. Even so, we have sufficient confidence in our assessment to **not treat Shadow Ledger as an alias, branch, or cluster of PLUMP SPIDER**.

This distinction matters because similarities in targets, tools, or techniques do not necessarily mean the same operators are behind them. In the Brazilian cybercrime landscape, different groups may target the same sector, reuse similar tools, and even operate within the same environments. **Attribution needs to consider the full body of evidence, not just what appears on the endpoint.**

Over nearly a year of tracking this activity, we have seen what the group kept, what it changed, and how **official notices,** ***ClickFix***, **and a trojanized Electron application based on BoostNote** became part of the same operation.

## How We Track This Operation

The **QuimeraX** ***CTI*** team tracks **Shadow Ledger** through threat monitoring, malware analysis, campaign correlation, and, when the same pattern appears in an environment under investigation, evidence collected through Incident Response. We also monitor the public-facing infrastructure abused by the group, including `.gov.br` and `.jus.br` websites that are turned into hosting infrastructure for “document” pages, official notice *links*, and *payloads*.

What matters here is recognizing a ***modus operandi*** that keeps repeating even as the domain, sender, and filename change.

The group is financially motivated. The impact we have observed throughout our monitoring is consistent with fraud, session theft, and the abuse of highly trusted infrastructure. This post focuses on how the group operates, persists, and evolves. We have intentionally left out names, internal cells within the group, and details that offer little value to defenders while only adding unnecessary noise.

## When the Operation Came to Light: Woovi and the Fake Official Notice

![](https://blog.quimerax.com/content/images/2026/09/image-21.png)

On **February 19, 2026**, the first public and private reports pointed to a possible compromise of **Woovi** (*CNPJ* 54.811.417/0001-63, *ISPB* 54811417).

The public statement described an *email* with the appearance of an official government communication and a malicious *PDF*. The campaign had four main characteristics:

1. **A legitimate institutional sender**, associated with the Amapá Civil Police (`@policiacivil.ap.gov.br`), with no indication of traditional sender spoofing.
2. **Language of authority**: summons, official notices, certificates, and legal warnings.
3. **The PDF as an intermediate stage**, rather than the final *payload*.
4. **Redirection to external infrastructure**, presented as a necessary step to “obtain the digital certificate.”

The flow looked like this:

1. The victim receives the institutional *email*.
2. Opens the *PDF*.
3. Clicks the “Digital Certificate” button or *link*.
4. Is redirected to an external server.
5. Downloads and executes an installer named to resemble an official document.

In that wave, the executable we observed was **`Certificado_PCAP.exe`**. The filename does the social engineering on its own. It looks like bureaucracy, not *malware*.

![](https://blog.quimerax.com/content/images/2026/09/image-22.png)

Public statement by Woovi’s CEO on February 19, 2026.

> “We suffered a zero-day attack.  
>  
> In keeping with Woovi’s commitment to full transparency, we are disclosing an unfortunate incident.  
>  
> Financial institutions face cyberattack attempts every day, and Woovi is no different. Cybersecurity attacks have become routine, and we are no exception.  
>  
> This time, however, we faced a more sophisticated scenario.  
>  
> A zero-day attack exploits vulnerabilities that are still unknown to system vendors and security tool providers. It is a rare and complex attack vector. The incident originated from a malicious PDF file received by email from an official government agency. Its code had not previously been identified by traditional antivirus mechanisms, and it compromised the PC of one of our employees.”

![](https://blog.quimerax.com/content/images/2026/09/image-23.png)

Malicious **PDF* used as a lure in the campaign, impersonating an official Civil Police communication and prompting the victim to install a supposed digital certificate.

> “THE CIVIL POLICE OF THE STATE OF PERNAMBUCO, through the undersigned police authority, pursuant to Article 144, § 4 of the Federal Constitution, Article 103 of the State Constitution, Article 4 and subsequent provisions of the Code of Criminal Procedure, Article 1, sole paragraph, of Law No. 9,296/96, and Article 10, § 3, in conjunction with Law No. 12,830/2013, hereby requests the following REGISTRATION DATA.  
>  
> **Encrypted Content**  
>  
> The content of this document is unavailable because it is protected by encryption. To decrypt and view the original text, the digital certificate must be installed.  
>  
> **Install Digital Certificate"**

The analysis of the infrastructure used in this campaign also revealed a **C2 panel identified in the interface as `Forever v1.0`**, used to manage connected hosts and execute tasks.

![](https://blog.quimerax.com/content/images/2026/09/image-24.png)

Authentication panel of the C2 infrastructure observed during the initial campaign associated with Woovi.

The technical assessment we made that day still holds nearly a year later. **The campaign’s success did not depend on a previously unknown software vulnerability.** It depended on an already compromised official account, a convincing document, and a user accustomed to complying with an official notice.

That is why the *hunting* began. If the initial vector was not a *zero-day*, then the same pattern could be hiding in other inboxes, other states, and other organizations. Woovi made the pattern visible. **The rest of the year showed that the incident was only one piece of a much larger operation with nationwide reach.**

## Who Is Shadow Ledger?

![](https://blog.quimerax.com/content/images/2026/09/image-25.png)

Shadow Ledger is a cybercrime group whose activity has been observed in Brazil since **September 2025**. Its attacks primarily target the **financial sector**, including payment institutions, *fintechs*, and service providers. At the same time, government organizations appear in the operation both as **targets** and as **infrastructure used to deliver the campaigns**.

In practice, the operation we have been tracking works on two fronts:

1. **Technical operations.** The group exploits exposed web services, hosting panels, and applications vulnerable to known flaws. Once compromised, this infrastructure is used to **maintain access and distribute additional stages of the campaign**.
2. **Social engineering.** Already compromised *email* accounts and websites are used to send official notices, summons, legal documents, and fake “digital certificates.” **Because the message comes from legitimate infrastructure, it arrives with a level of trust the attacker never had to build.**

The cycle feeds itself. A compromised municipal portal hosts the *malware*. A compromised police officer’s *email* account delivers the *PDF*. The corporate victim executes the file. The stolen session opens the door to financial systems. And new official notices begin arriving from new senders.

**These are not isolated incidents.** Throughout our monitoring and Incident Response engagements in 2026, we saw the same flow repeat across **several organizations**. The lure changed. The sender changed. The file changed. The C2 infrastructure changed. But the way the group operated remained largely the same.

This is exactly why treating each occurrence as an isolated incident becomes a problem. A defender sees a malicious official notice, a *ClickFix* attempt, or a suspicious browser extension. **Shadow Ledger used all of them as parts of the same operation.**

That is also why a defense strategy built solely around lists of *IoCs* ages quickly. Today, the sender may be from Amapá. Tomorrow, from another state. One week, the file is called `Certificado_PCAP.exe`; the next, `OficioPC.exe`. **The indicators keep changing, but the behavior remains.**

## One Operation, Multiple Arms

![](https://blog.quimerax.com/content/images/2026/09/image-26.png)

In early 2026, it was easy to look at these waves as separate campaigns. On one side, official notice *PDFs*, *QR codes*, and *ClickFix*. On the other, Inno Setup installers that ultimately led to a trojanized Electron application. Filenames changed. *Hosts* changed. **Even automated analysis from some** ***sandboxes*** **classified parts of the chain as legitimate software.**

Correlation tells a different story: **these are different arms of the same operation.**

Three pieces of evidence support this assessment:

1. **Shared public infrastructure.** The same compromised `.gov.br` and `.jus.br` portals distributed both **official notice** and ***ClickFix*** content, as well as installers from the **BoostNote** chain, within similar timeframes. Municipal government websites, protocol systems, document portals, and even infrastructure associated with public security appeared across both arms.
2. **The themes and logistics repeat.** Civil Police, summons, digital power of attorney, certificate. The legal-themed lure remains the same. What changes is the path to execution and the point at which we are able to observe the chain.
3. **A recurring build chain.** Even when the C2 changes, the installer continues to emerge from the same combination: a Delphi binary, Inno Setup packaging, and a Node.js/Electron *runtime* with a malicious `index.js`.

There is another important detail that helps explain why the official notice arm can make it through *email* filters. The messages are sent from **valid institutional accounts that have actually been compromised** and, as a result, may pass *SPF*, *DKIM*, and *DMARC* checks normally. This is not *spoofing*, where an attacker tries to impersonate a legitimate sender. **Here, the attacker is using an already compromised legitimate identity to send the official notice email.**

For a SOC, that distinction matters. An official notice that looks “clean” at the *email gateway* and an installer that raises no immediate red flags in a *sandbox* may be part of the same incident, just at different points in the chain. **When these arms are treated separately, the investigation becomes fragmented, and so does containment.**

## Timeline

The narrative below organizes the evidence in the order in which it was correlated. It is not a complete list of incidents, but rather a way to follow the evolution of the operation and understand **what the group kept, what changed, and how those changes allowed it to continue operating**.

## September 2025: The First Signs

The earliest signs we correlated with **Shadow Ledger** date back to **September 2025**. At that point, the Woovi incident was still months away from happening and becoming public. What we were already seeing, however, was an operation with a **clear financial objective** and the ability to turn compromised access into opportunities for financial activity.

This is important for understanding the rest of the story. **The operation did not begin with the February email.** That incident was simply the moment when the group hit a target that gained public visibility and, for us, became a starting point for connecting the evidence.

**Interest in payment environments and signs of monetization were already on our radar months before the February headlines, through other Incident Response engagements we had conducted.**

## January to February 2026: The Pipeline Was Already in Place

Before the Woovi incident gained public attention, samples and *emails* associated with the same group were already circulating. January and February show both arms operating in parallel: on one side, official notices accompanied by *PDFs*; on the other, installers leading to BoostNote.

In February, the operation gained public visibility. By then, the chain we would continue to observe repeatedly became much clearer:

- Compromised institutional *email* account;
- Official notice, summons, power of attorney, or certificate *PDF*;
- Bureaucratic-looking *loader*;
- Persistence through a trojanized BoostNote application;
- Additional stages delivered on demand.

Even at that point, we were already seeing **senders from different Brazilian states** and delivery *URLs* hosted on compromised public-sector portals. This was not an isolated campaign. **The infrastructure was already up and running.**

![](https://blog.quimerax.com/content/images/2026/09/image-27.png)

Official notice used as a lure in a Shadow Ledger campaign.

## February and March 2026: ClickFix Enters the Pipeline

In the weeks that followed, the group stopped relying solely on victims clicking through a *PDF*. **ClickFix** entered the pipeline.

The victim lands on an apparently legitimate website, often a compromised `.gov.br`, `.jus.br`, or `.com.br` domain, and is presented with a “verification” page resembling a Cloudflare anti-bot challenge. The instructions are simple: copy a command, open **Run** with **Win+R**, paste it, and confirm.

In one variant, the victim receives a PDF impersonating an official notice or summons from the Civil Police and containing a QR code. After scanning it, the victim is routed through a service that evaluates their profile before granting access to the same verification page, based on criteria defined by the attacker. The command we observed typically uses PowerShell to download and execute the next stage in memory.

From this point on, the initial access flow changes. **The browser is no longer the only stage**. By following the instructions displayed on the page, the victim brings execution directly into Windows. From there, *loaders*, commercial remote access tools, and the same persistence mechanism seen in other campaigns come into play, which we will explore shortly.

![](https://blog.quimerax.com/content/images/2026/09/image-28.png)

ClickFix page impersonating an anti-bot verification challenge on a compromised website.

## The Intermediaries Left Behind

*ClickFix* also revealed another characteristic of the operation: **the group did not rely solely on its own infrastructure to move victims to the next stage**. During our *hunting*, we identified several legitimate Brazilian websites, primarily `.com.br` domains, that had been compromised and turned into intermediary pages for the campaign.

Across several of these assets, we found **JavaScript injected directly into the HTML**. The code sent a request to `kak[.]is` and used the response to dynamically load the next stage of the campaign. This allowed a compromised legitimate website to become part of the *ClickFix* flow without requiring the attacker to host the entire chain on infrastructure under their own control.

![](https://blog.quimerax.com/content/images/2026/09/image-29.png)

JavaScript injected into a compromised `.com.br` page, responsible for contacting `kak[.]is` and dynamically loading the next stage of the campaign.

Tracking these intermediaries revealed another important detail. **Months later, some of the pages still contained the injected malicious code.** They were no longer redirecting new victims to *ClickFix* because the `kak[.]is` infrastructure used at that stage had stopped responding. The code itself, however, remained embedded in the HTML.

This highlights an important distinction between **disrupting the attack chain and remediating the compromise**. When an external dependency stops working, the campaign may stop delivering its next stage, but that does not necessarily mean the websites used as intermediaries have actually been remediated.

## March and April 2026: The Extension, Session Theft, and Nationwide Scale

![](https://blog.quimerax.com/content/images/2026/09/image-30.png)

The campaign gained a quieter stage: a **malicious Chrome extension**, presented as a certificate or browser security component.

The package we observed uses Manifest V3, a deceptive name such as **“Certificado SSL Chorme”**, and broad permissions, including `cookies` and `<all_urls>`. Once installed, the extension begins tracking the victim’s browsing activity and waits for them to access pages of interest, where it can act on already authenticated sessions.

![](https://blog.quimerax.com/content/images/2026/09/image-31.png)

Excerpt from the extension’s `manifest.json`, showing `cookies` permissions and `host_permissions` set to `<all_urls>`.

Code analysis revealed that **the targets were not hardcoded into the extension**. Target selection was controlled remotely through `goingg[.]is/whitelist.extension.txt`. Whenever navigation was completed, the accessed URL was compared against this list. If a match was found, the extension activated the next stage.

This allowed the operator to **change the monitored websites without reinstalling or distributing a new version of the extension**. The list was cached for only five minutes, after which it could be retrieved again from the campaign infrastructure.

The second component was even more interesting. The extension dynamically fetched the *script* `goingg[.]is/pipiteimosa.extension.js`, which was also cached for five minutes. When the victim accessed a selected address, the extension used `chrome.cookies.getAll()` to retrieve the *cookies* associated with that page and made them available within the browser’s main context through:

![](https://blog.quimerax.com/content/images/2026/09/image-32.png)

Excerpt from the malicious extension showing session cookies being made available through `window.unnregSession.cookies`.

The contents of `pipiteimosa.extension.js` were then injected directly into the page. **In practice, the extension created a bridge between the victim’s authenticated session and logic that could be remotely updated by the operator.**

This stage helps explain much of the impact observed later. The objective was no longer simply to obtain a password. The victim’s browser already contained sessions that had completed the authentication process and could provide access to administrative and financial systems.

**There is no need to “break” MFA when the target becomes a session that is already authenticated.**

Analysis of other artifacts from the same chain showed that the group had also developed a specific method to **install this extension in Chrome and Edge**.

Rather than relying solely on conventional user-driven installation, the code directly manipulates local browser profiles. In Chrome, it identifies the available profiles and modifies the `Preferences` and `Secure Preferences` files, enabling developer mode and adding the extension to the profile configuration. The extension is registered as external to the Chrome Web Store, with `from_webstore` set to `false` and permissions including `cookies`, `tabs`, `scripting`, and `<all_urls>`.

The code goes beyond simply editing these files. To keep the changes consistent with the integrity structures used by Chromium, **it recalculates the HMACs for the modified preferences and the `super_mac` stored in `Secure Preferences`**. After making the changes, the installer itself verifies whether the written values and their corresponding MACs remain valid.

The same logic was implemented for **Microsoft Edge**, with an additional step to locate the browser’s `resources.pak` file and identify a compatible *seed* based on the MACs already present in the profile. That *seed* is then used to recalculate the integrity structures after the modifications.

Another detail shows how the chain was designed to keep evolving. **The extension’s download address did not need to remain hardcoded in the installer.** The code retrieved external content from Pastebin to dynamically obtain the URL of the package to be downloaded. This allowed the operator to change where the extension was hosted without necessarily distributing a new version of the installer.

**The extension, therefore, was only one piece of the operation. A dedicated chain existed to place it inside the browser, while its target configuration and operational logic remained remotely controlled.**

![](https://blog.quimerax.com/content/images/2026/09/image-33.png)

Excerpt from the installer responsible for inserting the extension into Chrome’s preferences and recalculating the integrity structures in `Secure Preferences`.

During the same period, the official notice campaigns stopped looking regional. *Email* accounts belonging to Civil Police departments, state agencies, and municipal governments across **multiple Brazilian states** began appearing as senders, while compromised public-sector portals were used to host and distribute content. Paraná, Espírito Santo, Rio de Janeiro, São Paulo, Santa Catarina, Amapá, and other states appeared throughout the campaigns. The approach changed depending on the institution, **but the logic behind the attack remained the same**.

Across **Incident Response** engagements conducted by the QuimeraX team throughout 2026, this pattern appeared more than once: a compromised corporate workstation with an **installed extension** or ***custom stealer***, still-valid administrative and financial sessions, and an operator interested not only in credentials, **but in the access that identity already possessed**.

The pattern was not limited to a single public incident. **It resurfaced across several organizations.**

## May to August 2026: ".gov.br" Becomes a Delivery Factory and C2 Infrastructure Rotates with Each Wave

![](https://blog.quimerax.com/content/images/2026/09/image-34.png)

During the first half of 2026, both arms continued operating in parallel. Official notice *PDFs* received greater visibility early in the year, while the Inno/Electron chain remained active throughout the following months. Continuous monitoring began to reveal an increasingly clear characteristic: **the infrastructure changed from one wave to the next, but the way the group operated remained the same.**

In **May**, the operation was still combining compromised institutional *email* accounts, *ClickFix*, extensions, and the Inno/Electron chain. One wave used `policiacivilmg[.]com` as its C2, followed by `xx[.]kak[.]is`, while compromised senders appeared across different Brazilian states, including SP, SC, PR, AP, ES, and PE.

In one of the campaigns observed during this period, the *email* impersonated a **supplementary request from the Civil Police of Pernambuco** and used legal language to pressure the victim into accessing a supposed certificate. The *link* included in the message directed the victim to content hosted on compromised government infrastructure:

- `hxxps://poa[.]sp[.]gov[.]br/arquivofiscal/*`

![](https://blog.quimerax.com/content/images/2026/09/image-35.png)

Email used in a Shadow Ledger campaign, impersonating a request from the Civil Police of Pernambuco and directing the victim to content hosted on compromised `.gov.br` infrastructure.

> **MANDATORY SUPPLEMENT: Supplementary Request No. 024/2025 - Failure to Respond May Result in Procedural Sanctions - Civil Police of Pernambuco**  
>  
> The company **\[REDACTED\]**, CNPJ: **\[REDACTED\]**, in accordance with the provisions of Law No. 9,613/98 (combating money laundering) and BACEN Circular No. 3,978/2020, as well as Article 5 of Law No. 12,846/2013 (Anti-Corruption Law), is hereby required, on a mandatory basis, to update the registration information of the individual mentioned below.  
>  
> The requested information is as follows:  
>  
> **Linked phone number:** (XX) XXXXX-XXXX  
> **Registered email:** \[email\]  
> **Client:** \[REDACTED\]  
> **CPF/CNPJ:** \[number\]  
>  
> Additional details regarding the investigative procedure and the complete legal grounds are provided in the document attached to this message, which can be viewed after installing the certificate.  
>  
> **View ANC Certificate (Annex 1)**  
>  
> Sincerely,  
>  
> **\[REDACTED\]**  
> Police Chief  
> **Civil Police of Pernambuco / PC-BA Cooperation**

Just a few days later, the appearance of the persistence mechanism changed as well. The previously observed `boost.exe` was replaced by `draw.io.exe`, installed under `%LOCALAPPDATA%\EasySuiteAutoTool\`, alongside the `DocumentoPCPE.exe` *loader* and the C2 `pccvill[.]com`. **The names changed, but the same Electron runtime remained underneath.**

In **June**, the operation’s ability to continuously generate new themes became even more apparent. In addition to police notices, campaigns began using themes involving **court notices, money laundering, confidentiality, summons, requests, warrants, and notifications**. Some campaigns started using victim-specific paths such as `/levantamento/<id>`, while *loaders* appeared under names including `NotificacaoPCPE.exe`, `ProcuracaoDigital.exe`, and `RequerimentoPC.exe`.

Persistence also reappeared as `Boost Note.exe`, this time inside a directory named `QuickPlusSmartPlusator`. Meanwhile, the C2 infrastructure continued to rotate. `taaeiuep[.]com` appeared in one wave, followed by `dahieenloo[.]com` in the next. **Almost every new campaign introduced different infrastructure, while the initial access vector continued to rely on official documents and compromised public-sector assets.**

By **July**, monitoring these assets revealed the scale of the infrastructure behind the operation. Websites belonging to municipal governments, city councils, public pension funds, municipal protocol systems, and other government organizations were serving executables themed around **official notices, summons, powers of attorney, requests, and notifications**. In some cases, virtually any path under directories such as `/oficio/` or `/doc/` would deliver the *malware*. In others, addresses were created specifically for individual victims, making it more difficult for our team to track each victim precisely.

Files such as `OficioPC.exe` and `Procuracao_Digital.exe` repeated the behavior observed in previous waves, now associated with the C2 `zsxocjarsate[.]com`. On already compromised portals, we also observed the creation of new *email* accounts specifically for campaign distribution.

**In most cases, these portals were not the final target of the fraud. They had become part of the campaign infrastructure.** A `.gov.br` domain reduces suspicion, helps the campaign make it through security filters, and gives the operator paths that appear to belong to legitimate procedures, protocol systems, or public services.

By **August**, there was no sign that the operation was winding down. A new wave used senders associated with the education sector in Amapá, a “certificate” *ZIP* hosted at `marapoama[.]sp[.]gov[.]br`, the `CertificadoLeitorPCAP.exe` *loader*, and yet another C2, `eoplpfoepnwel[.]com`.

**New accounts. New files. New C2s. And the same cycle repeats once again.**

## September 2026: The Hosted Official Notice and search-ms

At the beginning of **September**, delivery still followed the pattern already seen in previous waves: `@policiacivil.pe.gov.br` and related email accounts, along with certificate-themed *ZIPs* and *EXEs* hosted on `previpaulista[.]pe[.]gov[.]br` and, once again, infrastructure in Marapoama.

Days later, the flow changed. The group began **hosting the fraudulent document itself directly on a compromised `.gov.br` domain**. The victim no longer depended solely on an attachment received by email. Upon accessing the address, they were presented with a page impersonating an official Civil Police notice, complete with **visual elements designed to resemble an official communication**, a document number, a request for banking information, and a button to “install digital certificate.”

![](https://blog.quimerax.com/content/images/2026/09/image-36.png)

Recent campaign (Sep/2026): fake official notice impersonating the Civil Police of Pernambuco, hosted at `marapoama[.]sp[.]gov[.]br/documento`, with a button prompting the victim to install a digital certificate.

In this wave, the *PDF* or *link* led to the `**search-ms:**` protocol. When clicked, it opened Windows Search pointing to a WebDAV share hosted on infrastructure belonging to the compromised municipality, at `mail[.]marapoama[.]sp[.]gov[.]br`. From there, the chain led the victim to a commercial RMM tool, Zoho Assist.

**The lure remained the official notice. This time, however, the path to execution had changed.**

![](https://blog.quimerax.com/content/images/2026/09/image-37.png)

The `search-ms` protocol used in the September 2026 campaign: Windows Search opens `Suporte.lnk` from `mail.marapoama.sp.gov.br`.

The messages were sent from **multiple email accounts belonging to the same state**, while the `/documento` path continued to be created individually for each target. Trust still came from compromised institutional infrastructure, but the directly downloaded executable was replaced by the use of a native Windows protocol, followed by remote access through an RMM tool.

The September campaigns also introduced **two new C2 domains**, `policiacivilba[.]com` and `policiacivilpe[.]com`. They follow the same *lookalike* pattern observed previously with `policiacivilmg[.]com`, `pccvill[.]com`, and `pccvioo[.]com`: `.com` domains designed to resemble Civil Police addresses, now referencing Bahia and Pernambuco.

The configuration observed on these *hosts* indicates that **the infrastructure was being prepared for new waves of the campaign**.

## What Remained: BoostNote

![](https://blog.quimerax.com/content/images/2026/09/2026-09-12_20-21-1.png)

While the infrastructure changed from one wave to the next, **the Electron host remained largely unchanged**. The filename, on the other hand, changed frequently.

In **May 2026**, the group moved away from the `boost.exe` observed in the previous wave and began persisting as `draw.io.exe` under `%LOCALAPPDATA%\EasySuiteAutoTool\`. In June, the same component reappeared as `Boost Note.exe`, this time under another fabricated directory, `QuickPlusSmartPlusator`. Later waves introduced names such as `Grape.exe` and `App.exe`.

Analysis of samples dating back to the February campaign reveals a relatively stable chain:

1. **Pre-stage:** a *PDF*, *QR code*, or *ClickFix* flow leads the victim to the *loader*.
2. **Loader:** an executable named after a certificate or official notice, compiled in Delphi and packaged with Inno Setup.
3. **Persistence:** installation of a trojanized Electron *host*, which may appear as BoostNote, `draw.io.exe`, or another name. Observed paths include `%LOCALAPPDATA%\ProSoftionTechMax\boost.exe`, `%LOCALAPPDATA%\EasySuiteAutoTool\draw.io.exe`, and `%LOCALAPPDATA%\QuickPlusSmartPlusator\Boost Note.exe`. Other waves use directories with fabricated product-like names such as `UltraSuiteSmartCoreware` and `ProSoftxUltraToolator`.
4. **Beacon:** the application’s `index.js` is deobfuscated, sends information about the workstation to the C2, and begins polling the server for new tasks.
5. **Next stages:** the C2 can return *JavaScript* to be executed within the process through `eval`, or deliver an executable that is written to `%TEMP%` and launched on the workstation.

The original BoostNote is a legitimate Electron-based note-taking application. For the attacker, this choice offers several advantages. **The process resembles productivity software, the installation directory looks like it belongs to a legitimate product, and C2 communication is hidden inside a common runtime.**

In more recent builds, even the BoostNote name begins to disappear. The binary takes on generic names such as `Grape.exe` or `App.exe` and may be extracted into temporary `is-*.tmp` directories. The intent appears straightforward: **change what defenders have learned to look for without abandoning what keeps the operation running.**

It is the malicious `index.js` that persists across these changes. Once deobfuscated, the same logic repeatedly appears:

- creates a persistent machine identifier under `%APPDATA%`;
- reads a campaign or affiliate tag stored alongside the installer;
- collects the computer and username;
- establishes persistence through a *Run* key and `setLoginItemSettings`;
- polls the C2 every few minutes for new tasks;
- executes whatever it receives, whether a *script* or a binary.

Throughout 2026, *redirectors*, IP addresses, domains, and filenames changed frequently. **The Electron host remained one of the most stable components of the operation.** Once the workstation moves beyond the initial stage of compromise, what remains running is no longer the *PDF*, the official notice, or the page used as a lure. It is this core component that maintains communication with the group’s infrastructure and enables the delivery of subsequent stages.

For *hunting*, this distinction matters. Blocking `Certificado_PCAP.exe` may stop that week’s wave. Looking for `ProSoftionTechMax`, `EasySuiteAutoTool`, `QuickPlusSmartPlusator`, unexpected executions of `boost.exe` or `draw.io.exe`, Electron *hosts* loading an obfuscated `index.js`, and *beacon* patterns associated with the family **allows defenders to hunt for the components the group continues to carry from one campaign to the next**.

![](https://blog.quimerax.com/content/images/2026/09/image-38.png)

## What Remained: The Backdoor Protocol

![](https://blog.quimerax.com/content/images/2026/09/image-39.png)

Domains and IP addresses are easy to replace in this operation. **The protocol used by the** ***beacon*** **changes far less frequently.**

Analysis of the samples revealed **at least two generations of communication** operating in parallel:

1. **GET generation.** Requests to paths following the format `/laravel.php?api=api&hash=<base64>&message=PT1n<base64>`, with data sent directly through the *query string*.
2. **POST generation (more common).** Requests to short paths, observed as `/nbw/`, `/f/`, `/zta`, and others, with a *JSON* body containing the machine identifier, `COMPUTERNAME`, `USERNAME`, and the tag associated with the campaign.

Despite the differences in communication, both generations share the same *build* chain involving Inno Setup, Electron, and `index.js`, as well as the same modular approach to delivering subsequent stages.

This is why simply blocking the domain only goes so far. The C2 used in one wave may be a Civil Police *lookalike*, such as `policiacivilmg[.]com`, while the next may use a completely random name such as `dahieenloo[.]com` or `zsxocjarsate[.]com`.

In some samples, **the C2 observed during analysis no longer even corresponds to the infrastructure that was active during the campaign**. The *delivery* infrastructure may remain hosted on a compromised `.gov.br` domain while the *beacon* points to infrastructure that has already been replaced.

Some of these C2s also sit behind *Cloudflare*, adding another layer between the observed domain and the origin infrastructure. **For defenders, the more durable indicator is not the domain. It is how the malware communicates and the chain that brings it into execution. Analyzing beaconing patterns is essential to detecting this behavior.**

## What Changed: ClickFix

![](https://blog.quimerax.com/content/images/2026/09/image-40.png)

*ClickFix* was one of the major adaptations to the initial access flow following the Woovi campaign.

In February, the victim still had to open the *PDF* and click on the supposed certificate. It worked, but it followed a more traditional document-based *phishing* flow. *ClickFix* expanded the group’s initial access options:

- the website could be hosted on an already compromised public-sector portal;
- the page impersonated a routine verification process;
- the requested action, opening **Run** with **Win+R**, pasting a command, and confirming, appeared to be part of the verification itself;
- execution moved out of the browser and directly into the victim’s system.

The infrastructure supporting this flow also expanded. First came `.gov.br` and `.jus.br` portals. Later, dozens of compromised `.com.br` websites began serving as intermediary pages. For defenders, the specific domain quickly loses value. **What remains is the sequence: apparently trusted infrastructure, a verification page, and execution performed by the victim.**

Across several waves, *ClickFix* did not replace the official notice. **It was added to the chain.** The email led to the *PDF*. The *PDF* led to the website, in some cases through a *QR code*. The website then instructed the victim to execute the command. In other campaigns, the order changed, but the objective remained the same: move execution from the browser into Windows.

There was also a filtering stage along the way. Intermediary services evaluated visitors before delivering the malicious page. This allowed *crawlers*, *sandboxes*, and visitors of no interest to the operator to receive different content or simply never progress further into the chain. **For a victim considered valid, the campaign continues. For automated analysis, it may look as if there is nothing there.**

For our monitoring, this was one of the first clear indications that **Shadow Ledger treats delivery as an adaptable part of the operation**. When one path begins to lose effectiveness, another can take its place without requiring the rest of the chain to change.

## What Changed: Official Notice Delivery

The official notice is one of the most consistent elements of the group’s social engineering. **The way it is delivered is not.**

### Phase 1: The Official Notice as an Attachment

In the campaign associated with Woovi, the flow was still relatively straightforward: email, *PDF*, and then the supposed “certificate.” Credibility came primarily from the compromised institutional sender and the official appearance of the document.

### Phase 2: The Official Notice as an Official Website

In the waves that followed, the group began to **use compromised public-sector websites as part of the delivery chain**. Email remained part of the operation, but victims were now directed to paths that appeared to belong to the portal itself:

- `/oficio`
- `/oficio/*`
- `/doc`
- `/documento`
- `/levantamento`
- `/intermediacao`
- `/procedimento`
- `/protocolo`

The `/*` matters here. **There is not necessarily a single file or URL to block. Different subpaths within the same directory may lead to the same malware.** In some campaigns, the *path* also included a unique identifier for each victim, making the address look like part of an individual case, protocol, or service request.

### Phase 3: The Official Notice at Scale

By **July and August 2026**, the operation had expanded beyond the document itself. The group began operating with **multiple compromised institutional email accounts**, reusing mail administration panels and rotating senders across different Brazilian states.

By June, email subjects were already being generated in bulk, with the recipient’s name dynamically replaced using what was effectively a template. In July, we observed new accounts being created inside already compromised municipal email environments specifically for campaign distribution. After compromising a city’s email system, for example, the operators could create addresses resembling `policiacivil@cidadedointerior.pr.gov.br`. **The legal language and institutional appearance remained.**

### Phase 4: The Official Notice Becomes a Web Page, and the Next Click Reaches Windows Search

In **September 2026**, the official notice no longer existed solely as an attachment or as a path leading to an `.exe` download. It was now presented as **a page hosted directly on a compromised `.gov.br` domain**, preserving the appearance of an official communication.

The next click used `search-ms:` to open Windows Search pointing to a WebDAV share hosted on the same compromised institutional infrastructure. In this wave, the next stage we observed led to a commercial RMM tool, Zoho Assist, rather than the same Electron *loader* seen in previous campaigns.

This evolution helps close the loop described at the beginning of this post. Compromising a `.gov.br` domain does not simply mean gaining control of a website. For the group, that access can provide:

- a place to host the *payload* or the official notice itself;
- a trusted domain that can help bypass filters and reduce suspicion;
- email accounts and, in some cases, WebDAV infrastructure to extend the chain;
- an institutional identity that makes the approach significantly more convincing.

For that reason, official notice delivery may be the clearest example of how **Shadow Ledger** evolved throughout 2026\. **The lure remained the same, but the way it was delivered kept evolving.** The C2 server, binary name, hashes, domain, path, and even the mechanism triggered by the click can change without changing the operation’s underlying objective.

## When Initial Access Meets a Permissive Environment

![](https://blog.quimerax.com/content/images/2026/09/image-41.png)

*Phishing* explains how the attacker gets in, but **it does not, by itself, explain why that access can go so far.**

Across our Incident Response engagements and the analyses conducted throughout our monitoring, we identified another recurring factor: **security controls that unnecessarily expanded the attack surface available after a workstation or identity had been compromised.**

This appeared in several forms.

**Back-office systems directly exposed to the Internet.** Administrative panels and internal systems were externally accessible without a clear operational need or without an additional layer of access control. For an operator who has just obtained a valid corporate session, finding this type of application significantly shortens the path between initial compromise and a sensitive system.

**Pix-related artifacts stored on hosts where they did not need to be.** In some environments, we found files and certificates used in validation and integration processes related to *cash-in* and *cash-out* flows stored on workstations or servers without a clear operational justification. The problem is not simply that the file exists. **It is the value that host gains once it is compromised.**

**Users with more privileges than necessary.** Accounts used for day-to-day activities retained access to systems, administrative panels, and functions that were not required for those activities. When that user’s session is stolen, the attacker inherits part of that access surface.

**Sensitive sessions concentrated on the same workstation.** Corporate email, administrative panels, financial platforms, and other systems remained authenticated within the same browser. In this scenario, compromising the endpoint no longer means gaining access to a single application. **It means taking over an identity that already has open paths into different parts of the operation.**

None of these issues, in isolation, explains the success of **Shadow Ledger**. The problem emerges when they come together.

**A phishing campaign does not need to end in the exploitation of a critical vulnerability when the compromised identity can already reach critical systems directly.**

This is where security maturity makes a difference. Segmenting back-office systems, restricting external exposure, enforcing least privilege, properly protecting certificates and other sensitive artifacts, and reducing the concentration of privileged sessions **will not stop the official notice from reaching the inbox, but they can drastically reduce what the attacker is able to do after the initial compromise.**

## What This Case Teaches Us

**Shadow Ledger** shows that an operation does not need a *zero-day* to be effective. **Persistence, scale, and the ability to adapt can be enough.**

After a year of monitoring, several lessons stand out:

- **A public incident does not represent the entire campaign.** Woovi made the pattern visible, but the operation already existed before that incident and continued to appear across other organizations in the months that followed.
- **An official sender does not mean a safe sender.** A genuinely compromised institutional account can pass *SPF*, *DKIM*, and *DMARC* checks while carrying a level of credibility that an unknown domain would struggle to achieve.
- **The official notice works because it exploits trust that already exists.** Police communications, summons, legal proceedings, powers of attorney, and certificates are not chosen at random. They are the kinds of communications that naturally create attention and urgency.
- **IoCs rotate. TTPs last longer.** From June onward, nearly every new wave introduced a different C2\. The Electron chain, *ClickFix*, the use of `search-ms:`, paths such as `/oficio`, and the *beacon’s* communication patterns provide more durable correlation points than the IP address or domain used in a single campaign.
- **Compromised public-sector websites become campaign infrastructure.** Municipal governments, city councils, public pension funds, and protocol portals are turned into hosts for documents, pages, and *payloads*. In many cases, the government organization is not the final target. **It is part of the path to it.**
- **Stealing a session changes the authentication problem.** With an already authenticated session in hand, the operator can reuse that access without necessarily going through the login flow and *MFA* challenge again.
- **A “clean” sample does not end the investigation.** An Inno installer, an Electron *host*, or an institutional notice may appear relatively unremarkable when analyzed in isolation. It is the correlation between them that reveals the campaign.
- **IR and CTI ultimately look at the same pieces from different perspectives.** The official notice seen during monitoring is the same one that later reappears on the *endpoint*. The C2 identified through intelligence supports *hunting*. And the artifact recovered during Incident Response helps explain the next wave.

None of this depends on a sophisticated operation in the cinematic sense. **It depends on time, scale, repetition, and adaptation.** **Shadow Ledger** found a way to exploit not only technical vulnerabilities, but something much harder to block: **the trust that companies and people place in legitimate institutions.**

# Conclusion

The Woovi case was the moment **Shadow Ledger** gained public visibility. For our monitoring, it was the point when an operation that had already been active began to reveal a much broader pattern.

Nearly a year later, the operation remains recognizable by the same elements: **trust in official communications, an adaptable delivery infrastructure, and the recurring use of Electron for persistence**. What changed was how the group reached its victims. *ClickFix*, new C2s with each wave, `draw.io.exe` replacing `boost.exe`, official notices hosted on `.gov.br` domains, `search-ms:`, and commercial RMM tools have made the operation much harder to contain with a single block.

Woovi was not an isolated incident. The same cycle resurfaced across **several other organizations** and relied on dozens of public-sector assets as part of its delivery infrastructure. As long as official communications carry trust by default, **that trust will continue to be exploited as part of the attack**.

At **QuimeraX**, this kind of monitoring is about going beyond what happened on the day of the incident. The goal is to understand **how the operation continues after the headlines have faded**, which components the group keeps, which ones it replaces, and where defenders may still be looking for last week’s domain, IP address, or file while the underlying behavior remains largely unchanged.

More than the story of a single incident, **Shadow Ledger** reinforces a simple idea: **in Brazil, institutional trust still functions as a security control.** We trust the domain, the sender, the document, and the appearance of an official communication. The group has learned to exploit exactly that.

**When that trust is compromised, the attacker no longer needs to look legitimate. They are already operating from infrastructure that is.**

**Want the QuimeraX team monitoring threats that could affect your organization?** 
**Request a demo and see QuimeraX in action: https://quimerax.com**

## Useful Indicators for Hunting

The list below is intentionally short. **Shadow Ledger’s infrastructure changes frequently**, so extensive lists of domains and IP addresses quickly become outdated.

For *hunting*, it is more valuable to start with the elements that survive infrastructure changes.

| Anchor                       | What to Look For                                                                                                                                                                                                             |
| ---------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Electron persistence**     | %LOCALAPPDATA%\\ProSoftionTechMax\\boost.exe, %LOCALAPPDATA%\\EasySuiteAutoTool\\draw.io.exe, %LOCALAPPDATA%\\QuickPlusSmartPlusator\\Boost Note.exe, as well as Grape.exe and App.exe under temporary is-\*.tmp directories |
| **Build chain**              | Delphi + Inno Setup installer loading a Node.js/Electron application with an obfuscated index.js                                                                                                                             |
| **Loader / official notice** | Executables with names such as Certificado\_\*, Oficio\*, Intimacao\*, Requerimento\*, Procuracao\*, and DocumentoPC\*, as well as documents such as Ofc.pdf                                                                 |
| **GET beacon**               | Requests to /laravel.php?api=api&hash= accompanied by message=PT1n                                                                                                                                                           |
| **POST beacon**              | POST /nbw/ containing a machine identifier, COMPUTERNAME, and USERNAME                                                                                                                                                       |
| **ClickFix / search-ms**     | Sequences involving Win+R followed by command pasting, a *QR code* embedded in a PDF, or a search-ms: URI pointing to WebDAV and files such as Suporte.lnk                                                                   |
| **Malicious extension**      | An extension installed outside the Chrome Web Store, presented as an SSL certificate or security component, with cookies and <all\_urls> permissions                                                                         |
| **Institutional delivery**   | Paths such as /oficio, /doc, /documento, /levantamento, /intermediacao, and /arquivofiscal serving executables, ZIP files, or official notice pages                                                                          |
| **Institutional email**      | .gov.br or .jus.br senders combined with official notices, summons, or certificate-themed content, including messages that pass SPF, DKIM, and DMARC checks                                                                  |
| **Post-compromise activity** | Unauthorized or unapproved RMM tools such as MasterRemote, MeshCentral, AnyDesk, or Zoho Assist, particularly on workstations used by users with administrative or financial access                                          |

The names used for persistence varied between `boost.exe`, `draw.io.exe`, `Boost Note.exe`, `Grape.exe`, and `App.exe`, while the operation also abused different commercial remote access tools.

## Historical IoCs

The list below consolidates ***IoCs*** observed between **September 2025 and September 2026** while tracking Shadow Ledger activity.

The group’s infrastructure changes frequently. For this reason, these indicators should be used primarily for **retrospective hunting, correlation, and investigation enrichment**, rather than as a permanent *blocklist*. All network indicators are presented in **defanged** form.

### Network: IP Addresses

The addresses below were associated, at different points in the operation, with infrastructure used for **C2, redirection, payload distribution, stealers, and campaign delivery**.

| Indicator                   | Observed Role                                                                       | Period       |
| --------------------------- | ----------------------------------------------------------------------------------- | ------------ |
| 79\[.\]110\[.\]49\[.\]32    | Redirector / hosting (80, 443, 3389)                                                | Feb 2026     |
| 79\[.\]110\[.\]49\[.\]5     | Redirector, successor to .32                                                        | Feb 2026     |
| 79\[.\]110\[.\]49\[.\]43    | Redirector / stealer, with AnyDesk on port 7070                                     | Feb–Mar 2026 |
| 195\[.\]177\[.\]94\[.\]94   | C2 / stealer associated with kapa\[.\]is and info\[.\]kak\[.\]is (3333, 3334, 8888) | Feb–Mar 2026 |
| 195\[.\]177\[.\]94\[.\]103  | Backend associated with the official notice arm                                     | Jan–Jul 2026 |
| 195\[.\]177\[.\]94\[.\]148  | C2                                                                                  | Mar 2026     |
| 195\[.\]177\[.\]94\[.\]14   | kak\[.\]is backend associated with the extension (443)                              | Mar 2026     |
| 195\[.\]177\[.\]94\[.\]64   | kak\[.\]is backend associated with the extension (80)                               | Mar 2026     |
| 94\[.\]154\[.\]32\[.\]112   | Stealer (3003, 3004, 3005)                                                          | Feb–Mar 2026 |
| 91\[.\]92\[.\]243\[.\]207   | Origin C2 associated with jmkkload\[.\]com, protected by Cloudflare                 | Mar 2026     |
| 91\[.\]92\[.\]241\[.\]181   | C2 associated with oficiospolicia\[.\]com                                           | Apr 2026     |
| 185\[.\]219\[.\]83\[.\]191  | Electron backdoor beacon                                                            | Jul 2026     |
| 188\[.\]137\[.\]246\[.\]189 | Beacon / associated C2                                                              | 2026         |
| 179\[.\]43\[.\]182\[.\]27   | Management / aggregation host                                                       | Mar 2026     |
| 179\[.\]43\[.\]167\[.\]210  | Stealer (3333, 3334)                                                                | Apr 2026     |
| 194\[.\]59\[.\]30\[.\]191   | Backend for .js scripts                                                             | Apr 2026     |
| 200\[.\]189\[.\]123\[.\]155 | SMTP server used in campaign (smtp01\[.\]pr\[.\]gov\[.\]br)                         | Mar 2026     |
| 104\[.\]249\[.\]10\[.\]245  | Delivery redirector                                                                 | Mar 2026     |
| 132\[.\]148\[.\]180\[.\]83  | ClickFix infrastructure associated with compracertanfe\[.\]com                      | May 2026     |
| 94\[.\]154\[.\]32\[.\]35    | Payload distribution via /d/out.txt                                                 | May 2026     |
| 158\[.\]94\[.\]208\[.\]120  | C2 associated with policiacivilmg\[.\]com                                           | May 2026     |
| 195\[.\]177\[.\]94\[.\]62   | Associated C2                                                                       | May 2026     |

## Network: C2 Domains and Campaign Infrastructure

The domains below were observed serving different roles within the operation, including **C2, exfiltration, payload distribution, ClickFix, malicious extension infrastructure, and redirection**.

They are listed separately from compromised institutional domains, such as `.gov.br` and `.jus.br`, which the group used as *delivery* infrastructure.

| Indicator                                     | Observed Role                                                 |
| --------------------------------------------- | ------------------------------------------------------------- |
| kapa\[.\]is                                   | C2 / beacon (/f/e/)                                           |
| kak\[.\]is                                    | C2 / stealer / extension                                      |
| xx\[.\]kak\[.\]is                             | ClickFix catalog / payload distribution                       |
| yy\[.\]kak\[.\]is                             | ClickFix catalog                                              |
| info\[.\]kak\[.\]is                           | Exfiltration (3333, 3334, 8888)                               |
| goingg\[.\]is                                 | C2 associated with the extension                              |
| ext\[.\]kak\[.\]is                            | Extension panel, earlier infrastructure                       |
| ext\[.\]goingg\[.\]is                         | Extension panel, later infrastructure                         |
| jmkkload\[.\]com                              | C2 protected by Cloudflare                                    |
| oficiospolicia\[.\]com                        | C2 panel                                                      |
| policiacivilmg\[.\]com                        | Police-themed C2                                              |
| pccvill\[.\]com                               | Police-themed C2                                              |
| pccvioo\[.\]com                               | Police-themed C2                                              |
| policiacivilba\[.\]com                        | Police-themed C2, referencing Bahia                           |
| policiacivilpe\[.\]com                        | Police-themed C2, referencing Pernambuco                      |
| dahieenloo\[.\]com                            | Randomly named C2                                             |
| psznaoehteeh\[.\]com                          | Randomly named C2                                             |
| eeresofeuae\[.\]com                           | Randomly named C2                                             |
| zsxocjarsate\[.\]com                          | C2 associated with POST /nbw/ beaconing                       |
| taaeiuep\[.\]com                              | C2 associated with the Inno / digital power of attorney chain |
| api\[.\]sessionvalidator\[.\]com              | Tasking framework                                             |
| compliancemetrics\[.\]net                     | Tasking framework                                             |
| oauth\[.\]openvpnet\[.\]com                   | Associated C2                                                 |
| conformidade\[.\]certificadosoficiais\[.\]com | Redirector using a ZeroSSL certificate                        |
| antiddos-protection\[.\]net                   | Campaign infrastructure                                       |
| compracertanfe\[.\]com                        | ClickFix infrastructure                                       |
| checkeronlinehuman\[.\]com                    | Infrastructure associated with the judicial-themed wave       |
| eoplpfoepnwel\[.\]com                         | C2 observed in Aug 2026                                       |

## Delivery, C2, and Associated Infrastructure URLs

The URLs below were observed at different stages of the campaigns, including **redirection, payload delivery, ClickFix, C2 communication, extension distribution, and abuse of compromised institutional infrastructure**.

The presence of a `.gov.br` domain in this table represents a **historical observation of abuse or compromise during the campaign**. It does not mean that the asset remains compromised today and **should not be interpreted as a recommendation to block the institutional domain**.

| Indicator                                                                                                         | Observed Context                                                                |
| ----------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| hxxps://79\[.\]110\[.\]49\[.\]32/.certificados.ap.gov.br                                                          | Redirector used in the campaign associated with Woovi                           |
| hxxps://kapa\[.\]is/f/e/                                                                                          | BoostNote beacon / C2                                                           |
| hxxp://<c2>/laravel.php?api=api&hash=                                                                             | GET beacon pattern observed in the earlier generation                           |
| hxxps://zsxocjarsate\[.\]com/nbw/                                                                                 | POST beacon observed in 2026                                                    |
| hxxps://kak\[.\]is/pipiteimosa.extension.js                                                                       | Script associated with the stealer / extension                                  |
| hxxps://kak\[.\]is/te\_3\_la.js                                                                                   | Additional script associated with the stealer                                   |
| hxxps://kak\[.\]is/urlzzz.php                                                                                     | Campaign endpoint                                                               |
| hxxps://kak\[.\]is/\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_/chrome\_extension.zip                     | Extension package distribution                                                  |
| hxxps://kak\[.\]is/temp/WinPython/preto.py                                                                        | Auxiliary artifact                                                              |
| hxxps://xx\[.\]kak\[.\]is/\_verosss\_/russo.exe                                                                   | Payload distribution                                                            |
| hxxps://xx\[.\]kak\[.\]is/1.txt                                                                                   | Catalog associated with ClickFix                                                |
| hxxps://yy\[.\]kak\[.\]is/1.txt                                                                                   | Catalog associated with ClickFix                                                |
| hxxps://xx\[.\]kak\[.\]is/\_clkfx/lnk1.txt                                                                        | ClickFix catalog, Apr 2026                                                      |
| hxxps://goingg\[.\]is/whitelist.extension.txt                                                                     | Dynamic extension configuration                                                 |
| hxxps://goingg\[.\]is/pipiteimosa.extension.js                                                                    | Remote extension payload                                                        |
| hxxps://ext\[.\]kak\[.\]is/                                                                                       | Panel associated with the extension                                             |
| hxxps://ext\[.\]goingg\[.\]is/                                                                                    | Later panel associated with the extension                                       |
| hxxps://jmkkload\[.\]com/                                                                                         | C2                                                                              |
| hxxps://cmdca\[.\]go\[.\]gov\[.\]br/download                                                                      | ClickFix / MasterRemote delivery                                                |
| hxxps://conseg\[.\]ssp\[.\]go\[.\]gov\[.\]br/COAF-POLICIAFEDERAL.exe                                              | Executable hosted on compromised .gov.br infrastructure                         |
| hxxps://prodoc\[.\]ap\[.\]gov\[.\]br                                                                              | ClickFix / official notice                                                      |
| hxxps://timon\[.\]ma\[.\]gov\[.\]br                                                                               | Delivery infrastructure shared between the official notice and installer chains |
| hxxps://protocolo\[.\]sorocaba\[.\]sp\[.\]gov\[.\]br                                                              | Delivery infrastructure shared between the official notice and installer chains |
| hxxps://cee\[.\]rr\[.\]gov\[.\]br/oficio                                                                          | Official notice delivery                                                        |
| hxxps://sistemas\[.\]cabo\[.\]pe\[.\]gov\[.\]br/oficio.php                                                        | Official notice delivery                                                        |
| hxxps://sg\[.\]plantaalagoas\[.\]al\[.\]gov\[.\]br/oficios                                                        | Official notice delivery                                                        |
| hxxps://efis\[.\]sipom\[.\]pm\[.\]ms\[.\]gov\[.\]br/oficio/                                                       | Official notice delivery                                                        |
| hxxps://sisct\[.\]cidadania\[.\]gov\[.\]br/comunidades-web/baixar.jsp                                             | Associated delivery infrastructure                                              |
| hxxps://ibrep\[.\]alfamaoraculo\[.\]com\[.\]br/core/components/Certificado\_Pcap.exe                              | Dropper / MasterRemote                                                          |
| hxxp://previpaulista\[.\]pe\[.\]gov\[.\]br/oficio/\*                                                              | IntimacaoPCAP.exe delivery                                                      |
| hxxps://camaraparaguacu\[.\]sp\[.\]gov\[.\]br/doc/\*                                                              | RequerimentoPC.exe delivery                                                     |
| hxxps://camaraparaguacu\[.\]sp\[.\]gov\[.\]br/intermediacao                                                       | RequerimentoPC.exe delivery                                                     |
| hxxps://camaraparaguacu\[.\]sp\[.\]gov\[.\]br/oficio                                                              | RequerimentoPC.exe delivery                                                     |
| hxxps://floresdegoias\[.\]go\[.\]gov\[.\]br/levantamento                                                          | NotificacaoPCPE.exe delivery                                                    |
| hxxps://areal\[.\]rj\[.\]gov\[.\]br/levantamento/\*                                                               | ProcuracaoDigital.exe delivery, with a victim-specific path                     |
| hxxps://prefeituradepoa\[.\]sp\[.\]gov\[.\]br/doc                                                                 | Delivery observed on Jul 13, 2026                                               |
| hxxps://funrespol\[.\]pc\[.\]ro\[.\]gov\[.\]br/documento                                                          | Delivery observed on Jul 13, 2026                                               |
| hxxps://funprecon\[.\]pe\[.\]gov\[.\]br/arquivos/extension.zip                                                    | Extension package hosted on compromised .gov.br infrastructure                  |
| hxxps://funprecon\[.\]pe\[.\]gov\[.\]br/ys.php?p=                                                                 | Tiny File Manager observed on compromised infrastructure                        |
| hxxps://www\[.\]funrespol\[.\]pc\[.\]ro\[.\]gov\[.\]br/anexos\_evento/uploads/fm.php                              | File manager observed on compromised infrastructure                             |
| hxxps://dipol\[.\]policiacivil\[.\]sp\[.\]gov\[.\]br/conferirviatura/imagens/2e39069c345e175af74a031a2d9523a7.php | Web shell observed on compromised infrastructure                                |
| hxxp://94\[.\]154\[.\]32\[.\]35/d/out.txt                                                                         | Payload distribution, May 2026                                                  |
| hxxps://poa\[.\]sp\[.\]gov\[.\]br/arquivofiscal/tboKmG/dDvBqC                                                     | DocumentoPCPE.exe delivery, May 2026                                            |
| hxxps://aquisicoes\[.\]seplag\[.\]mt\[.\]gov\[.\]br/sigacontrato/subsystems/comum/signkit.jsp?yd=                 | Delivery associated with the judicial-themed wave, Jun 2026                     |
| hxxps://dd\[.\]checkeronlinehuman\[.\]com/static/js/dashboard.runtime.js                                          | Script associated with the judicial-themed wave, Jun 2026                       |
| hxxps://dd\[.\]checkeronlinehuman\[.\]com/v2/agents/register                                                      | Agent registration observed in the judicial-themed wave, Jun 2026               |
| hxxps://areal\[.\]rj\[.\]gov\[.\]br/levantamento/5gr67j                                                           | Example of a victim-specific path                                               |
| hxxps://camaraparaguacu\[.\]sp\[.\]gov\[.\]br/doc/kdkddl                                                          | Delivery observed in Jun 2026                                                   |
| hxxps://dahieenloo\[.\]com/                                                                                       | C2 observed in Jun 2026                                                         |
| hxxp://sigdoc\[.\]ap\[.\]gov\[.\]br/public/verArquivo\[.\]jsf                                                     | Delivery observed in Aug 2026                                                   |
| hxxp://marapoama\[.\]sp\[.\]gov\[.\]br/CertificadoPCAP\[.\]zip                                                    | Certificate-themed ZIP, Aug 2026                                                |
| hxxps://previpaulista\[.\]pe\[.\]gov\[.\]br/oficio/\*/\*                                                          | Delivery pattern observed in Sep 2026                                           |
| hxxps://marapoama\[.\]sp\[.\]gov\[.\]br/CertificadoPCPE.zip                                                       | Certificate-themed ZIP, Sep 2026                                                |
| hxxps://marapoama\[.\]sp\[.\]gov\[.\]br/documento                                                                 | Official notice hosted directly on the compromised portal, Sep 2026             |
| hxxps://marapoama\[.\]sp\[.\]gov\[.\]br/documento/\*/\*                                                           | Target-specific path, Sep 2026                                                  |
| search-ms:query=Suporte.lnk&crumb=location:\\\\\\mail\[.\]marapoama\[.\]sp\[.\]gov\[.\]br\\DavWWWRoot             | Windows Search pointing to WebDAV, Sep 2026                                     |
| hxxps://eoplpfoepnwel\[.\]com/                                                                                    | C2 observed in Aug 2026                                                         |
| hxxps://policiacivilba\[.\]com/                                                                                   | Police-themed C2 observed in Sep 2026                                           |
| hxxps://policiacivilpe\[.\]com/                                                                                   | Police-themed C2 observed in Sep 2026                                           |
| assist\[.\]zoho\[.\]com                                                                                           | Zoho Assist observed as an RMM tool in the search-ms: wave, Sep 2026            |

## Files, Hashes, and Persistence Artifacts

The artifacts below were observed across different waves of the operation and include **loaders, documents, Electron chain components, extension packages, and files used for persistence**.

Hashes are presented as historical indicators. Filenames, on the other hand, should be correlated with paths, behavior, and other signals from the chain, as they may change between campaigns.

| File                                            | Hash                                                                    | Observed Context                        |
| ----------------------------------------------- | ----------------------------------------------------------------------- | --------------------------------------- |
| Certificado\_PCAP.exe                           | MD5 05d8c7d4bc49a2da4587535abae9b06d                                    | Loader, Feb 2026                        |
| Sample with no preserved filename               | MD5 8bd9f1e7a0b11a0a08c1205983412286                                    | Campaign sample, Mar 2026               |
| Sample with no preserved filename               | SHA256 e81c9825936156152f52ab17caae50cd5a457c58ea714880629f5dcd2637c9cf | Same sample, Mar 2026                   |
| IntimacaoPCAP.exe                               | MD5 998c57f34bbfdbd71c39e05756c9845d                                    | Delivery via .gov.br                    |
| IntimacaoPCAP.exe                               | SHA1 785575764c27ed7c86084286f7470b6bed86b9eb                           | Same sample                             |
| IntimacaoPCAP.exe                               | SHA256 3ca047f71d398a05894163ccb0fe385583329805b370d7e9396f32187facd8a9 | Same sample                             |
| RequerimentoPC.exe                              | MD5 98d1e966010f88e0bf26f414f2f0f55a                                    | Loader / delivery                       |
| RequerimentoPC.exe                              | SHA1 ea18659fa43b9005b85eb7bc788dc7fedd2f9f8b                           | Same sample                             |
| RequerimentoPC.exe                              | SHA256 8b3f0c4984c5448977c3e7e8330504b949a1c4fc47772697ceb07beb4710b87d | Same sample                             |
| NotificacaoPCPE.exe                             | MD5 145888cca508ed7333317097d03fde32                                    | Loader / delivery                       |
| NotificacaoPCPE.exe                             | SHA1 16a9e74ac547e1ddd616e2022131fd78e0ab5d3e                           | Same sample                             |
| NotificacaoPCPE.exe                             | SHA256 9832843da2c6057bd8a522820b947e507b1c5560f07c3449ba917592efd5439f | Same sample                             |
| ProcuracaoDigital.exe                           | MD5 3dbd4dbbe24685648ca5ae7e751cef46                                    | Loader / delivery                       |
| ProcuracaoDigital.exe                           | SHA1 f5858f1a4afc204841ed284117b99fa3c7f447ee                           | Same sample                             |
| ProcuracaoDigital.exe                           | SHA256 ebaf5aded88ec40f16f1448586633ff44d907abb2d8990cb52ba7f6a6e405831 | Same sample                             |
| OficioPC.exe                                    | MD5 c4d6bc8a0dc4f9df9021c2311dbb1056                                    | Same operational family                 |
| OficioPC.exe                                    | SHA1 7320857bc6c2dd69a44b602fc298d4af472cb246                           | Same sample                             |
| OficioPC.exe                                    | SHA256 47786e32b166bc027ace509daf3ecd8253ebf2cbe2de32926529005fc03d374f | Same sample                             |
| Procuracao\_Digital.exe                         | MD5 15801b64c170752caaf1fa329f946382                                    | Loader / delivery                       |
| Procuracao\_Digital.exe                         | SHA1 ddeb7b9b6bf4e88544ef0576c74726805148d4fe                           | Same sample                             |
| Procuracao\_Digital.exe                         | SHA256 e0dae1a04b7a3b2ae07377b0fd00681e9633532788870b3709a9e149f3ccf0e0 | Same sample                             |
| index.js                                        | SHA256 71f69978667dc421e7edf8885e9f3bde9dd527d9f7974228c9a6eac84c2ab71c | Electron host backdoor                  |
| DocumentoPCPE.exe / draw.io.exe                 | MD5 e02e55554ea7f50a9da7bbd7fb48fdf9                                    | EasySuiteAutoTool persistence, May 2026 |
| DocumentoPCPE.exe / draw.io.exe                 | SHA256 6dc6d269b5c5c717d7ac06f7305b7362f22742c87e77049c1670bae3c8e18560 | Same sample                             |
| Sample with no preserved filename               | MD5 20896fdc683273d4d5575b8d932ddc5a                                    | Judicial-themed wave, Jun 2026          |
| Sample with no preserved filename               | SHA1 a90d804c4e7b651d29abd787a267020cba44e272                           | Same sample                             |
| Sample with no preserved filename               | SHA256 bfc632e5040adbec76ae73c182be3910fc314bde743ca2a69c2a0c8e95c0fdc2 | Same sample                             |
| Ofc.pdf                                         | MD5 91349675b6a5ad547babe05121da98d4                                    | Official notice, Aug 2026               |
| Ofc.pdf                                         | SHA1 e3075bce3897a48a0e46b8314688251297dc4a06                           | Same sample                             |
| Ofc.pdf                                         | SHA256 333c60dd1c4e54d0700b91a666f8588f3c8b2639d82dee7e2454f8e0881eb860 | Same sample                             |
| CertificadoLeitorPCAP.exe / CertificadoPCPE.exe | MD5 f76e7b97a0589a1965d734b669afed40                                    | Loader, Aug–Sep 2026                    |
| CertificadoLeitorPCAP.exe / CertificadoPCPE.exe | SHA1 54791e8b81719a81771a19ac3a87832ea2ad56c9                           | Same sample                             |
| CertificadoLeitorPCAP.exe / CertificadoPCPE.exe | SHA256 8ccfbc26fee9c4fd20566abfbb43587334e1060a65f4027eb957c34761250199 | Same sample                             |
| CertificadoPCPE.zip                             | MD5 323168687c4ec30a6b54cc700f457962                                    | Package, Sep 2026                       |
| CertificadoPCPE.zip                             | SHA1 ba75d2760d552d70d4ac49afbea9b8603a541cc5                           | Same package                            |
| CertificadoPCPE.zip                             | SHA256 1160ab6ef017a9bf2d02a6401883741cefd6fd3fbe0c2da464a9f1f818f08c8e | Same package                            |

## Persistence, Extension, and Remote Access Tools

In addition to hashes, several endpoint artifacts remained useful for *hunting* even as the infrastructure and sample names changed.

| Indicator                                              | Observed Context                                               |
| ------------------------------------------------------ | -------------------------------------------------------------- |
| %LOCALAPPDATA%\\ProSoftionTechMax\\boost.exe           | Trojanized BoostNote host                                      |
| %LOCALAPPDATA%\\EasySuiteAutoTool\\draw.io.exe         | Alternative persistence, May 2026                              |
| %LOCALAPPDATA%\\QuickPlusSmartPlusator\\Boost Note.exe | Persistence observed in Jun 2026                               |
| %APPDATA%\\setup.txt                                   | Auxiliary artifact associated with the draw.io.exe wave        |
| Grape.exe / App.exe                                    | Renamed Electron binary                                        |
| UltraSuiteSmartCoreware / ProSoftxUltraToolator        | Installation directories with fabricated product-like names    |
| setLoginItemSettings \+ Run key                        | Persistence mechanisms observed in index.js                    |
| Certificado SSL Chorme                                 | Name observed in the malicious MV3 extension                   |
| extension.zip                                          | Extension package hosted on compromised .gov.br infrastructure |
| cookies \+ <all\_urls>                                 | Permissions observed in the extension                          |
| MasterRemote                                           | RMM observed as a subsequent stage                             |
| ScreenConnect                                          | RMM observed as a subsequent stage                             |
| MeshCentral                                            | RMM observed as a subsequent stage                             |
| AnyDesk                                                | Additional RMM, including a service observed on port 7070      |
| Zoho Assist (assist\[.\]zoho\[.\]com)                  | RMM observed in the search-ms: wave, Sep 2026                  |

## Observed Institutional Senders

The accounts and domains below were observed as **delivery channels in different campaigns associated with Shadow Ledger**. In several cases, the messages originated from compromised legitimate institutional infrastructure, allowing the email to retain characteristics expected of authentic communications.

**The presence of an address or domain in this table represents a historical observation. It does not mean that the account, user, or institution remains compromised today and should not be interpreted as a recommendation to block the domain.**

| Indicator                                                      | Observed Context                                                                                          |
| -------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- |
| @policiacivil\[.\]ap\[.\]gov\[.\]br                            | Sending domain observed in the campaign associated with Woovi and in subsequent waves                     |
| deccon\[@\]policiacivil\[.\]ap\[.\]gov\[.\]br                  | Sender observed in Feb 2026                                                                               |
| deiai\[@\]policiacivil\[.\]ap\[.\]gov\[.\]br                   | Sender observed in Feb 2026                                                                               |
| @pc\[.\]es\[.\]gov\[.\]br                                      | Domain used to send PDFs                                                                                  |
| wagno\[.\]manguinhos\[@\]pc\[.\]es\[.\]gov\[.\]br              | Sender used to deliver PDFs                                                                               |
| @pcivil\[.\]rj\[.\]gov\[.\]br                                  | Domain used to send PDFs                                                                                  |
| @pc\[.\]sp\[.\]gov\[.\]br                                      | Domain used to send PDFs                                                                                  |
| @pr\[.\]gov\[.\]br                                             | Domain observed in the Paraná wave, involving different government agencies                               |
| smtp01\[.\]pr\[.\]gov\[.\]br                                   | SMTP server observed in the Paraná wave                                                                   |
| @sesp\[.\]es\[.\]gov\[.\]br                                    | Domain used to send PDFs                                                                                  |
| loginam\[.\]sesp\[.\]es\[.\]gov\[.\]br                         | Asset associated with the campaign                                                                        |
| policiacivil\[@\]ituporanga\[.\]sc\[.\]gov\[.\]br              | Sender used to deliver PDFs                                                                               |
| alinesouza\[.\]guaira\[@\]pr\[.\]gov\[.\]br                    | Sender used to deliver PDFs                                                                               |
| willian\[.\]kesseli\[@\]appa\[.\]pr\[.\]gov\[.\]br             | Sender used to deliver PDFs                                                                               |
| luisgregorini\[@\]der\[.\]pr\[.\]gov\[.\]br                    | Sender used to deliver PDFs                                                                               |
| rebjuliocesar\[@\]seed\[.\]pr\[.\]gov\[.\]br                   | Sender used to deliver PDFs                                                                               |
| mariaalzenir\[@\]idr\[.\]pr\[.\]gov\[.\]br                     | Sender used to deliver PDFs                                                                               |
| urbanismo\[@\]quatrobarras\[.\]pr\[.\]gov\[.\]br               | Sender used to deliver PDFs                                                                               |
| anabreda\[@\]seed\[.\]pr\[.\]gov\[.\]br                        | Sender used to deliver PDFs                                                                               |
| cartorioprocon\[@\]cascavel\[.\]pr\[.\]gov\[.\]br              | Sender used to deliver PDFs                                                                               |
| policacivil\[@\]cravinhos\[.\]sp\[.\]gov\[.\]br                | Sender observed in May 2026, using a narrative related to the Civil Police of Rio Grande do Norte (PC/RN) |
| juan\[.\]cartacho\[@\]sejus\[.\]es\[.\]gov\[.\]br              | Sender observed in May 2026                                                                               |
| jose\[.\]azevedo\[@\]pc\[.\]pb\[.\]gov\[.\]br                  | Sender observed in May 2026                                                                               |
| jose\[.\]luzia\[@\]policiacivil\[.\]pe\[.\]gov\[.\]br          | Sender observed in May 2026                                                                               |
| contato\[@\]tjto\[.\]jus\[.\]br                                | Sender associated with the judicial-themed wave, Jun 2026                                                 |
| gpequeno\[@\]mprj\[.\]rj\[.\]br                                | Sender observed in Jun 2026                                                                               |
| antonio\[.\]pereira\[@\]ipa\[.\]br                             | Sender observed in Jun 2026                                                                               |
| antonio\[.\]pereira\[@\]pm\[.\]pe\[.\]gov\[.\]br               | Sender observed in Jun 2026                                                                               |
| \*\[@\]ipa\[.\]br / \*\[@\]pm\[.\]pe\[.\]gov\[.\]br            | Sending domains observed in Jun 2026                                                                      |
| ana\[.\]paula\[.\]silva\[@\]sjdh\[.\]pe\[.\]gov\[.\]br         | Sender observed in Jun 2026                                                                               |
| rogerio\[.\]lima\[@\]seap\[.\]pe\[.\]gov\[.\]br                | Sender observed in Jun 2026                                                                               |
| policia\[.\]civil\[@\]itaipulandia\[.\]pr\[.\]gov\[.\]br       | Sender observed in Jul 2026                                                                               |
| delegadomarcost\*\[@\]itaipulandia\[.\]pr\[.\]gov\[.\]br       | Mailbox naming pattern observed in Jul 2026 campaign activity                                             |
| cpvpeb\[@\]seed\[.\]ap\[.\]gov\[.\]br                          | Sender observed in Aug 2026                                                                               |
| ncc\[@\]seed\[.\]ap\[.\]gov\[.\]br                             | Sender observed in Aug 2026                                                                               |
| ivson\[.\]felix\[@\]corregedoria\[.\]sds\[.\]pe\[.\]gov\[.\]br | Sender observed in Sep 2026                                                                               |
| \*\[@\]corregedoria\[.\]sds\[.\]pe\[.\]gov\[.\]br              | Sending domain observed in Sep 2026                                                                       |
| ivson\[.\]felix\[@\]policiacivil\[.\]pe\[.\]gov\[.\]br         | Sender observed in Sep 2026                                                                               |
| \*\[@\]policiacivil\[.\]pe\[.\]gov\[.\]br                      | Sending domain observed in Sep 2026                                                                       |

## ClickFix Intermediary Sites

In addition to institutional infrastructure, a wave observed in **April 2026** used several `.com.br` websites as **intermediary pages in the ClickFix chain**.

As with the government assets, these are **historical indicators of abuse observed during the investigation**. The presence of a domain in this list does not mean that the website remains compromised today.

| Indicator                                    |
| -------------------------------------------- |
| www\[.\]dragermanasilvestri\[.\]com\[.\]br   |
| www\[.\]acpunica\[.\]com\[.\]br              |
| assistancesolucoesabc\[.\]com\[.\]br         |
| belices\[.\]com\[.\]br                       |
| brumalucelli\[.\]com\[.\]br                  |
| carolinaterapiaintegrativa\[.\]com\[.\]br    |
| biofur\[.\]com\[.\]br                        |
| chegoupagou\[.\]com\[.\]br                   |
| concursosresultado\[.\]com\[.\]br            |
| www\[.\]jddev\[.\]com\[.\]br                 |
| www\[.\]mstortti\[.\]com\[.\]br              |
| www\[.\]redesindicos\[.\]com\[.\]br          |
| www\[.\]netlm\[.\]com\[.\]br                 |
| www\[.\]refricorpos\[.\]com\[.\]br           |
| www\[.\]resultfacil\[.\]com\[.\]br           |
| www\[.\]talkhere\[.\]com\[.\]br              |
| www\[.\]totalservicosadm\[.\]com\[.\]br      |
| www\[.\]transguiterraplanagem\[.\]com\[.\]br |
| www\[.\]vocefaznfe\[.\]com\[.\]br            |
| www\[.\]vivendadolago\[.\]com\[.\]br         |
| plataformajacitraining\[.\]com\[.\]br        |
| www\[.\]wmempresas\[.\]com\[.\]br            |
| osnirestevam\[.\]com\[.\]br                  |
| slamdigital\[.\]com\[.\]br                   |
| www\[.\]beefpassion\[.\]com\[.\]br           |
| ebinterchange\[.\]com\[.\]br                 |

## Compromised Institutional Infrastructure

Throughout the investigation, we identified a significant number of **compromised municipal, state-level, and other institutional assets** associated with **Shadow Ledger** campaigns.

These assets appeared in different roles, including **payload hosting, official notice pages, ClickFix, extension distribution, and other components of the delivery chain**. In some cases, the same infrastructure was reused across different waves of the operation.

The list below **is not exhaustive** and represents historical observations. The presence of a domain does not mean that the asset remains compromised today and **should not be interpreted as a recommendation to block the institutional domain**.

| State  | Observed Domains                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **AL** | chapreta\[.\]al\[.\]gov\[.\]br, sg\[.\]plantaalagoas\[.\]al\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **AP** | prodoc\[.\]ap\[.\]gov\[.\]br, sigdoc\[.\]ap\[.\]gov\[.\]br, seed\[.\]ap\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **BA** | gaviao\[.\]ba\[.\]gov\[.\]br, itiuba\[.\]ba\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **ES** | loginam\[.\]sesp\[.\]es\[.\]gov\[.\]br, sejus\[.\]es\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **GO** | camaravalparaiso\[.\]go\[.\]gov\[.\]br, cmvg\[.\]go\[.\]gov\[.\]br, floresdegoias\[.\]go\[.\]gov\[.\]br, jataiprevi\[.\]go\[.\]gov\[.\]br, simolandia\[.\]go\[.\]gov\[.\]br, cmdca\[.\]go\[.\]gov\[.\]br, conseg\[.\]ssp\[.\]go\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **MA** | timon\[.\]ma\[.\]gov\[.\]br, candidomendes\[.\]ma\[.\]gov\[.\]br, centraldomaranhao\[.\]ma\[.\]gov\[.\]br, cmarari\[.\]ma\[.\]gov\[.\]br, cmcentraldomaranhao\[.\]ma\[.\]gov\[.\]br, cmigarapegrande\[.\]ma\[.\]gov\[.\]br, cmlagodosrodrigues\[.\]ma\[.\]gov\[.\]br, cmmarajadosena\[.\]ma\[.\]gov\[.\]br, cmpauloramos\[.\]ma\[.\]gov\[.\]br, cmpocaodepedras\[.\]ma\[.\]gov\[.\]br, cmpresidentesarney\[.\]ma\[.\]gov\[.\]br, cmsantaines\[.\]ma\[.\]gov\[.\]br, cmsaoraimundododocabezerra\[.\]ma\[.\]gov\[.\]br, cmvitorinofreire\[.\]ma\[.\]gov\[.\]br, conceicaodolagoacu\[.\]ma\[.\]gov\[.\]br, governadorarcher\[.\]ma\[.\]gov\[.\]br, jenipapodosvieiras\[.\]ma\[.\]gov\[.\]br, mataroma\[.\]ma\[.\]gov\[.\]br, palmeirandia\[.\]ma\[.\]gov\[.\]br, presidentemedici\[.\]ma\[.\]gov\[.\]br, saobeneditodoriopreto\[.\]ma\[.\]gov\[.\]br, tufilandia\[.\]ma\[.\]gov\[.\]br, vitorinofreire\[.\]ma\[.\]gov\[.\]br |
| **MG** | camaradelassance\[.\]mg\[.\]gov\[.\]br, camaradouradoquara\[.\]mg\[.\]gov\[.\]br, camaraestreladosul\[.\]mg\[.\]gov\[.\]br, camaralontra\[.\]mg\[.\]gov\[.\]br, camaravarginha\[.\]mg\[.\]gov\[.\]br, cascalhorico\[.\]mg\[.\]gov\[.\]br, douradoquara\[.\]mg\[.\]gov\[.\]br, estreladosul\[.\]mg\[.\]gov\[.\]br, lontra\[.\]mg\[.\]gov\[.\]br, previlagoa\[.\]mg\[.\]gov\[.\]br, saojoaodamata\[.\]mg\[.\]gov\[.\]br, uniprevdivino\[.\]mg\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **MS** | treslagoasprevidencia\[.\]ms\[.\]gov\[.\]br, efis\[.\]sipom\[.\]pm\[.\]ms\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **MT** | seplag\[.\]mt\[.\]gov\[.\]br, aplicacao\[.\]cbm\[.\]mt\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **PB** | camaradecacimbadedentro\[.\]pb\[.\]gov\[.\]br, camarapedralavrada\[.\]pb\[.\]gov\[.\]br, pc\[.\]pb\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **PE** | funprecon\[.\]pe\[.\]gov\[.\]br, previpaulista\[.\]pe\[.\]gov\[.\]br, sistemas\[.\]cabo\[.\]pe\[.\]gov\[.\]br, policiacivil\[.\]pe\[.\]gov\[.\]br, sjdh\[.\]pe\[.\]gov\[.\]br, seap\[.\]pe\[.\]gov\[.\]br, corregedoria\[.\]sds\[.\]pe\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **PI** | camaramunicipaldesaofranciscodopiaui\[.\]pi\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **PR** | anahy\[.\]pr\[.\]gov\[.\]br, brasilandiadosul\[.\]pr\[.\]gov\[.\]br, cidelparna\[.\]pr\[.\]gov\[.\]br, cmperobal\[.\]pr\[.\]gov\[.\]br, farol\[.\]pr\[.\]gov\[.\]br, novalaranjeiras\[.\]pr\[.\]gov\[.\]br, quatropontes\[.\]pr\[.\]gov\[.\]br, tuneirasdooeste\[.\]pr\[.\]gov\[.\]br, itaipulandia\[.\]pr\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **RJ** | areal\[.\]rj\[.\]gov\[.\]br, prevsul\[.\]rj\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **RO** | funrespol\[.\]pc\[.\]ro\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **RR** | bonfim\[.\]rr\[.\]gov\[.\]br, canta\[.\]rr\[.\]gov\[.\]br, uiramuta\[.\]rr\[.\]gov\[.\]br, cee\[.\]rr\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **RS** | amaralferrador\[.\]rs\[.\]gov\[.\]br, camaraamaralferrador\[.\]rs\[.\]gov\[.\]br, camaraeldorado\[.\]rs\[.\]gov\[.\]br, camaranovapalma\[.\]rs\[.\]gov\[.\]br, camarapinhalgrande\[.\]rs\[.\]gov\[.\]br, camarasantamargaridadosul\[.\]rs\[.\]gov\[.\]br, circ\[.\]rs\[.\]gov\[.\]br, cmfaxinaldosoturno\[.\]rs\[.\]gov\[.\]br, cmvdonafrancisca\[.\]rs\[.\]gov\[.\]br, donafrancisca\[.\]rs\[.\]gov\[.\]br, faxinaldosoturno\[.\]rs\[.\]gov\[.\]br, ivora\[.\]rs\[.\]gov\[.\]br, jari\[.\]rs\[.\]gov\[.\]br, novapalma\[.\]rs\[.\]gov\[.\]br, pinhalgrande\[.\]rs\[.\]gov\[.\]br, restingaseca\[.\]rs\[.\]gov\[.\]br, xangrila\[.\]rs\[.\]gov\[.\]br                                                                                                                                                                                                                                                                     |
| **SP** | camaraparaguacu\[.\]sp\[.\]gov\[.\]br, cmauriflama\[.\]sp\[.\]gov\[.\]br, cmnovacastilho\[.\]sp\[.\]gov\[.\]br, condemat\[.\]sp\[.\]gov\[.\]br, ferrazdevasconcelos\[.\]sp\[.\]gov\[.\]br, marapoama\[.\]sp\[.\]gov\[.\]br, mail\[.\]marapoama\[.\]sp\[.\]gov\[.\]br, prefeituradepoa\[.\]sp\[.\]gov\[.\]br, poa\[.\]sp\[.\]gov\[.\]br, protocolo\[.\]sorocaba\[.\]sp\[.\]gov\[.\]br, cravinhos\[.\]sp\[.\]gov\[.\]br                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |