Meet Shadow Ledger: The Group That Hijacks Official Authority to Hit Brazil’s Financial Sector

Meet Shadow Ledger: The Group That Hijacks Official Authority to Hit Brazil’s Financial Sector
Meet the group that does not hesitate to compromise official authorities, then use them against the financial sector, with the trust that only a .gov.br sender can carry.

On February 19, 2026, Woovi’s name began circulating across social media and tech communities. The company, which operates in the payments and Pix ecosystem, had been linked to an incident. That same day, its CEO issued a statement: the incident was believed to have started with an email sent from a government domain and a PDF, described at the time as part of the exploitation of a zero-day vulnerability.

At first glance, it looked like a sophisticated, isolated attack. The QuimeraX Cyber Threat Intelligence (CTI) team saw it differently.

The attack vector matched a phishing campaign that was already circulating against Brazil’s financial sector. The messages were being sent from genuinely compromised institutional infrastructure, without relying on traditional spoofing. The PDF prompted the victim to download what appeared to be a “digital certificate.” At the time, there was no technical evidence that a zero-day was being exploited.

That public incident made the pattern visible. But it was not the beginning of the story.

Throughout our monitoring, we identified the same pattern across several other organizations in the financial and services ecosystem. Payment institutions, fintechs, service providers, and adjacent organizations appeared in the same attack flow throughout 2026. We are not naming them here. For defenders, understanding how the operation works matters more than knowing the full list of victims.

The hunting that followed, along with the monitoring we have maintained ever since, revealed an operation that was older, more persistent, and more industrialized than that single incident initially suggested. At QuimeraX, we track this activity as a distinct cluster, which we call Shadow Ledger.

Why Shadow Ledger and Not PLUMP SPIDER?

During our monitoring of these campaigns, we identified analyses from other security teams linking part of this activity to PLUMP SPIDER, another Brazilian threat group known for targeting the financial sector.

Our assessment is different.

QuimeraX tracks Shadow Ledger as a group distinct from PLUMP SPIDER. This separation is not based solely on differences in modus operandi, infrastructure, or TTPs.

Throughout the investigation, we correlated information about both operations that goes beyond purely technical analysis. We have evidence, including non-public information about individuals involved in these groups' operations, that supports our assessment that they are distinct threat actors.

For operational reasons, we will not disclose identities, sources, or other details in this post that could expose the investigation. Even so, we have sufficient confidence in our assessment to not treat Shadow Ledger as an alias, branch, or cluster of PLUMP SPIDER.

This distinction matters because similarities in targets, tools, or techniques do not necessarily mean the same operators are behind them. In the Brazilian cybercrime landscape, different groups may target the same sector, reuse similar tools, and even operate within the same environments. Attribution needs to consider the full body of evidence, not just what appears on the endpoint.

Over nearly a year of tracking this activity, we have seen what the group kept, what it changed, and how official notices, ClickFix, and a trojanized Electron application based on BoostNote became part of the same operation.

How We Track This Operation

The QuimeraX CTI team tracks Shadow Ledger through threat monitoring, malware analysis, campaign correlation, and, when the same pattern appears in an environment under investigation, evidence collected through Incident Response. We also monitor the public-facing infrastructure abused by the group, including .gov.br and .jus.br websites that are turned into hosting infrastructure for “document” pages, official notice links, and payloads.

What matters here is recognizing a modus operandi that keeps repeating even as the domain, sender, and filename change.

The group is financially motivated. The impact we have observed throughout our monitoring is consistent with fraud, session theft, and the abuse of highly trusted infrastructure. This post focuses on how the group operates, persists, and evolves. We have intentionally left out names, internal cells within the group, and details that offer little value to defenders while only adding unnecessary noise.

When the Operation Came to Light: Woovi and the Fake Official Notice

On February 19, 2026, the first public and private reports pointed to a possible compromise of Woovi (CNPJ 54.811.417/0001-63, ISPB 54811417).

The public statement described an email with the appearance of an official government communication and a malicious PDF. The campaign had four main characteristics:

  1. A legitimate institutional sender, associated with the Amapá Civil Police (@policiacivil.ap.gov.br), with no indication of traditional sender spoofing.
  2. Language of authority: summons, official notices, certificates, and legal warnings.
  3. The PDF as an intermediate stage, rather than the final payload.
  4. Redirection to external infrastructure, presented as a necessary step to “obtain the digital certificate.”

The flow looked like this:

  1. The victim receives the institutional email.
  2. Opens the PDF.
  3. Clicks the “Digital Certificate” button or link.
  4. Is redirected to an external server.
  5. Downloads and executes an installer named to resemble an official document.

In that wave, the executable we observed was Certificado_PCAP.exe. The filename does the social engineering on its own. It looks like bureaucracy, not malware.

Public statement by Woovi’s CEO on February 19, 2026.
“We suffered a zero-day attack.

In keeping with Woovi’s commitment to full transparency, we are disclosing an unfortunate incident.

Financial institutions face cyberattack attempts every day, and Woovi is no different. Cybersecurity attacks have become routine, and we are no exception.

This time, however, we faced a more sophisticated scenario.

A zero-day attack exploits vulnerabilities that are still unknown to system vendors and security tool providers. It is a rare and complex attack vector. The incident originated from a malicious PDF file received by email from an official government agency. Its code had not previously been identified by traditional antivirus mechanisms, and it compromised the PC of one of our employees.”
Malicious PDF used as a lure in the campaign, impersonating an official Civil Police communication and prompting the victim to install a supposed digital certificate.
“THE CIVIL POLICE OF THE STATE OF PERNAMBUCO, through the undersigned police authority, pursuant to Article 144, § 4 of the Federal Constitution, Article 103 of the State Constitution, Article 4 and subsequent provisions of the Code of Criminal Procedure, Article 1, sole paragraph, of Law No. 9,296/96, and Article 10, § 3, in conjunction with Law No. 12,830/2013, hereby requests the following REGISTRATION DATA.

Encrypted Content

The content of this document is unavailable because it is protected by encryption. To decrypt and view the original text, the digital certificate must be installed.

Install Digital Certificate"

The analysis of the infrastructure used in this campaign also revealed a C2 panel identified in the interface as Forever v1.0, used to manage connected hosts and execute tasks.

Authentication panel of the C2 infrastructure observed during the initial campaign associated with Woovi.

The technical assessment we made that day still holds nearly a year later. The campaign’s success did not depend on a previously unknown software vulnerability. It depended on an already compromised official account, a convincing document, and a user accustomed to complying with an official notice.

That is why the hunting began. If the initial vector was not a zero-day, then the same pattern could be hiding in other inboxes, other states, and other organizations. Woovi made the pattern visible. The rest of the year showed that the incident was only one piece of a much larger operation with nationwide reach.

Who Is Shadow Ledger?

Shadow Ledger is a cybercrime group whose activity has been observed in Brazil since September 2025. Its attacks primarily target the financial sector, including payment institutions, fintechs, and service providers. At the same time, government organizations appear in the operation both as targets and as infrastructure used to deliver the campaigns.

In practice, the operation we have been tracking works on two fronts:

  1. Technical operations. The group exploits exposed web services, hosting panels, and applications vulnerable to known flaws. Once compromised, this infrastructure is used to maintain access and distribute additional stages of the campaign.
  2. Social engineering. Already compromised email accounts and websites are used to send official notices, summons, legal documents, and fake “digital certificates.” Because the message comes from legitimate infrastructure, it arrives with a level of trust the attacker never had to build.

The cycle feeds itself. A compromised municipal portal hosts the malware. A compromised police officer’s email account delivers the PDF. The corporate victim executes the file. The stolen session opens the door to financial systems. And new official notices begin arriving from new senders.

These are not isolated incidents. Throughout our monitoring and Incident Response engagements in 2026, we saw the same flow repeat across several organizations. The lure changed. The sender changed. The file changed. The C2 infrastructure changed. But the way the group operated remained largely the same.

This is exactly why treating each occurrence as an isolated incident becomes a problem. A defender sees a malicious official notice, a ClickFix attempt, or a suspicious browser extension. Shadow Ledger used all of them as parts of the same operation.

That is also why a defense strategy built solely around lists of IoCs ages quickly. Today, the sender may be from Amapá. Tomorrow, from another state. One week, the file is called Certificado_PCAP.exe; the next, OficioPC.exe. The indicators keep changing, but the behavior remains.

One Operation, Multiple Arms

In early 2026, it was easy to look at these waves as separate campaigns. On one side, official notice PDFs, QR codes, and ClickFix. On the other, Inno Setup installers that ultimately led to a trojanized Electron application. Filenames changed. Hosts changed. Even automated analysis from some sandboxes classified parts of the chain as legitimate software.

Correlation tells a different story: these are different arms of the same operation.

Three pieces of evidence support this assessment:

  1. Shared public infrastructure. The same compromised .gov.br and .jus.br portals distributed both official notice and ClickFix content, as well as installers from the BoostNote chain, within similar timeframes. Municipal government websites, protocol systems, document portals, and even infrastructure associated with public security appeared across both arms.
  2. The themes and logistics repeat. Civil Police, summons, digital power of attorney, certificate. The legal-themed lure remains the same. What changes is the path to execution and the point at which we are able to observe the chain.
  3. A recurring build chain. Even when the C2 changes, the installer continues to emerge from the same combination: a Delphi binary, Inno Setup packaging, and a Node.js/Electron runtime with a malicious index.js.

There is another important detail that helps explain why the official notice arm can make it through email filters. The messages are sent from valid institutional accounts that have actually been compromised and, as a result, may pass SPF, DKIM, and DMARC checks normally. This is not spoofing, where an attacker tries to impersonate a legitimate sender. Here, the attacker is using an already compromised legitimate identity to send the official notice email.

For a SOC, that distinction matters. An official notice that looks “clean” at the email gateway and an installer that raises no immediate red flags in a sandbox may be part of the same incident, just at different points in the chain. When these arms are treated separately, the investigation becomes fragmented, and so does containment.

Timeline

The narrative below organizes the evidence in the order in which it was correlated. It is not a complete list of incidents, but rather a way to follow the evolution of the operation and understand what the group kept, what changed, and how those changes allowed it to continue operating.

September 2025: The First Signs

The earliest signs we correlated with Shadow Ledger date back to September 2025. At that point, the Woovi incident was still months away from happening and becoming public. What we were already seeing, however, was an operation with a clear financial objective and the ability to turn compromised access into opportunities for financial activity.

This is important for understanding the rest of the story. The operation did not begin with the February email. That incident was simply the moment when the group hit a target that gained public visibility and, for us, became a starting point for connecting the evidence.

Interest in payment environments and signs of monetization were already on our radar months before the February headlines, through other Incident Response engagements we had conducted.

January to February 2026: The Pipeline Was Already in Place

Before the Woovi incident gained public attention, samples and emails associated with the same group were already circulating. January and February show both arms operating in parallel: on one side, official notices accompanied by PDFs; on the other, installers leading to BoostNote.

In February, the operation gained public visibility. By then, the chain we would continue to observe repeatedly became much clearer:

  • Compromised institutional email account;
  • Official notice, summons, power of attorney, or certificate PDF;
  • Bureaucratic-looking loader;
  • Persistence through a trojanized BoostNote application;
  • Additional stages delivered on demand.

Even at that point, we were already seeing senders from different Brazilian states and delivery URLs hosted on compromised public-sector portals. This was not an isolated campaign. The infrastructure was already up and running.

Official notice used as a lure in a Shadow Ledger campaign.

February and March 2026: ClickFix Enters the Pipeline

In the weeks that followed, the group stopped relying solely on victims clicking through a PDF. ClickFix entered the pipeline.

The victim lands on an apparently legitimate website, often a compromised .gov.br, .jus.br, or .com.br domain, and is presented with a “verification” page resembling a Cloudflare anti-bot challenge. The instructions are simple: copy a command, open Run with Win+R, paste it, and confirm.

In one variant, the victim receives a PDF impersonating an official notice or summons from the Civil Police and containing a QR code. After scanning it, the victim is routed through a service that evaluates their profile before granting access to the same verification page, based on criteria defined by the attacker. The command we observed typically uses PowerShell to download and execute the next stage in memory.

From this point on, the initial access flow changes. The browser is no longer the only stage. By following the instructions displayed on the page, the victim brings execution directly into Windows. From there, loaders, commercial remote access tools, and the same persistence mechanism seen in other campaigns come into play, which we will explore shortly.

ClickFix page impersonating an anti-bot verification challenge on a compromised website.

The Intermediaries Left Behind

ClickFix also revealed another characteristic of the operation: the group did not rely solely on its own infrastructure to move victims to the next stage. During our hunting, we identified several legitimate Brazilian websites, primarily .com.br domains, that had been compromised and turned into intermediary pages for the campaign.

Across several of these assets, we found JavaScript injected directly into the HTML. The code sent a request to kak[.]is and used the response to dynamically load the next stage of the campaign. This allowed a compromised legitimate website to become part of the ClickFix flow without requiring the attacker to host the entire chain on infrastructure under their own control.

JavaScript injected into a compromised .com.br page, responsible for contacting kak[.]is and dynamically loading the next stage of the campaign.

Tracking these intermediaries revealed another important detail. Months later, some of the pages still contained the injected malicious code. They were no longer redirecting new victims to ClickFix because the kak[.]is infrastructure used at that stage had stopped responding. The code itself, however, remained embedded in the HTML.

This highlights an important distinction between disrupting the attack chain and remediating the compromise. When an external dependency stops working, the campaign may stop delivering its next stage, but that does not necessarily mean the websites used as intermediaries have actually been remediated.

March and April 2026: The Extension, Session Theft, and Nationwide Scale

The campaign gained a quieter stage: a malicious Chrome extension, presented as a certificate or browser security component.

The package we observed uses Manifest V3, a deceptive name such as “Certificado SSL Chorme”, and broad permissions, including cookies and <all_urls>. Once installed, the extension begins tracking the victim’s browsing activity and waits for them to access pages of interest, where it can act on already authenticated sessions.

Excerpt from the extension’s manifest.json, showing cookies permissions and host_permissions set to <all_urls>.

Code analysis revealed that the targets were not hardcoded into the extension. Target selection was controlled remotely through goingg[.]is/whitelist.extension.txt. Whenever navigation was completed, the accessed URL was compared against this list. If a match was found, the extension activated the next stage.

This allowed the operator to change the monitored websites without reinstalling or distributing a new version of the extension. The list was cached for only five minutes, after which it could be retrieved again from the campaign infrastructure.

The second component was even more interesting. The extension dynamically fetched the script goingg[.]is/pipiteimosa.extension.js, which was also cached for five minutes. When the victim accessed a selected address, the extension used chrome.cookies.getAll() to retrieve the cookies associated with that page and made them available within the browser’s main context through:

Excerpt from the malicious extension showing session cookies being made available through window.unnregSession.cookies.

The contents of pipiteimosa.extension.js were then injected directly into the page. In practice, the extension created a bridge between the victim’s authenticated session and logic that could be remotely updated by the operator.

This stage helps explain much of the impact observed later. The objective was no longer simply to obtain a password. The victim’s browser already contained sessions that had completed the authentication process and could provide access to administrative and financial systems.

There is no need to “break” MFA when the target becomes a session that is already authenticated.

Analysis of other artifacts from the same chain showed that the group had also developed a specific method to install this extension in Chrome and Edge.

Rather than relying solely on conventional user-driven installation, the code directly manipulates local browser profiles. In Chrome, it identifies the available profiles and modifies the Preferences and Secure Preferences files, enabling developer mode and adding the extension to the profile configuration. The extension is registered as external to the Chrome Web Store, with from_webstore set to false and permissions including cookies, tabs, scripting, and <all_urls>.

The code goes beyond simply editing these files. To keep the changes consistent with the integrity structures used by Chromium, it recalculates the HMACs for the modified preferences and the super_mac stored in Secure Preferences. After making the changes, the installer itself verifies whether the written values and their corresponding MACs remain valid.

The same logic was implemented for Microsoft Edge, with an additional step to locate the browser’s resources.pak file and identify a compatible seed based on the MACs already present in the profile. That seed is then used to recalculate the integrity structures after the modifications.

Another detail shows how the chain was designed to keep evolving. The extension’s download address did not need to remain hardcoded in the installer. The code retrieved external content from Pastebin to dynamically obtain the URL of the package to be downloaded. This allowed the operator to change where the extension was hosted without necessarily distributing a new version of the installer.

The extension, therefore, was only one piece of the operation. A dedicated chain existed to place it inside the browser, while its target configuration and operational logic remained remotely controlled.

Excerpt from the installer responsible for inserting the extension into Chrome’s preferences and recalculating the integrity structures in Secure Preferences.

During the same period, the official notice campaigns stopped looking regional. Email accounts belonging to Civil Police departments, state agencies, and municipal governments across multiple Brazilian states began appearing as senders, while compromised public-sector portals were used to host and distribute content. Paraná, Espírito Santo, Rio de Janeiro, São Paulo, Santa Catarina, Amapá, and other states appeared throughout the campaigns. The approach changed depending on the institution, but the logic behind the attack remained the same.

Across Incident Response engagements conducted by the QuimeraX team throughout 2026, this pattern appeared more than once: a compromised corporate workstation with an installed extension or custom stealer, still-valid administrative and financial sessions, and an operator interested not only in credentials, but in the access that identity already possessed.

The pattern was not limited to a single public incident. It resurfaced across several organizations.

May to August 2026: ".gov.br" Becomes a Delivery Factory and C2 Infrastructure Rotates with Each Wave

During the first half of 2026, both arms continued operating in parallel. Official notice PDFs received greater visibility early in the year, while the Inno/Electron chain remained active throughout the following months. Continuous monitoring began to reveal an increasingly clear characteristic: the infrastructure changed from one wave to the next, but the way the group operated remained the same.

In May, the operation was still combining compromised institutional email accounts, ClickFix, extensions, and the Inno/Electron chain. One wave used policiacivilmg[.]com as its C2, followed by xx[.]kak[.]is, while compromised senders appeared across different Brazilian states, including SP, SC, PR, AP, ES, and PE.

In one of the campaigns observed during this period, the email impersonated a supplementary request from the Civil Police of Pernambuco and used legal language to pressure the victim into accessing a supposed certificate. The link included in the message directed the victim to content hosted on compromised government infrastructure:

  • hxxps://poa[.]sp[.]gov[.]br/arquivofiscal/*
Email used in a Shadow Ledger campaign, impersonating a request from the Civil Police of Pernambuco and directing the victim to content hosted on compromised .gov.br infrastructure.
MANDATORY SUPPLEMENT: Supplementary Request No. 024/2025 - Failure to Respond May Result in Procedural Sanctions - Civil Police of Pernambuco

The company [REDACTED], CNPJ: [REDACTED], in accordance with the provisions of Law No. 9,613/98 (combating money laundering) and BACEN Circular No. 3,978/2020, as well as Article 5 of Law No. 12,846/2013 (Anti-Corruption Law), is hereby required, on a mandatory basis, to update the registration information of the individual mentioned below.

The requested information is as follows:

Linked phone number: (XX) XXXXX-XXXX
Registered email: [email]
Client: [REDACTED]
CPF/CNPJ: [number]

Additional details regarding the investigative procedure and the complete legal grounds are provided in the document attached to this message, which can be viewed after installing the certificate.

View ANC Certificate (Annex 1)

Sincerely,

[REDACTED]
Police Chief
Civil Police of Pernambuco / PC-BA Cooperation

Just a few days later, the appearance of the persistence mechanism changed as well. The previously observed boost.exe was replaced by draw.io.exe, installed under %LOCALAPPDATA%\EasySuiteAutoTool\, alongside the DocumentoPCPE.exe loader and the C2 pccvill[.]com. The names changed, but the same Electron runtime remained underneath.

In June, the operation’s ability to continuously generate new themes became even more apparent. In addition to police notices, campaigns began using themes involving court notices, money laundering, confidentiality, summons, requests, warrants, and notifications. Some campaigns started using victim-specific paths such as /levantamento/<id>, while loaders appeared under names including NotificacaoPCPE.exe, ProcuracaoDigital.exe, and RequerimentoPC.exe.

Persistence also reappeared as Boost Note.exe, this time inside a directory named QuickPlusSmartPlusator. Meanwhile, the C2 infrastructure continued to rotate. taaeiuep[.]com appeared in one wave, followed by dahieenloo[.]com in the next. Almost every new campaign introduced different infrastructure, while the initial access vector continued to rely on official documents and compromised public-sector assets.

By July, monitoring these assets revealed the scale of the infrastructure behind the operation. Websites belonging to municipal governments, city councils, public pension funds, municipal protocol systems, and other government organizations were serving executables themed around official notices, summons, powers of attorney, requests, and notifications. In some cases, virtually any path under directories such as /oficio/ or /doc/ would deliver the malware. In others, addresses were created specifically for individual victims, making it more difficult for our team to track each victim precisely.

Files such as OficioPC.exe and Procuracao_Digital.exe repeated the behavior observed in previous waves, now associated with the C2 zsxocjarsate[.]com. On already compromised portals, we also observed the creation of new email accounts specifically for campaign distribution.

In most cases, these portals were not the final target of the fraud. They had become part of the campaign infrastructure. A .gov.br domain reduces suspicion, helps the campaign make it through security filters, and gives the operator paths that appear to belong to legitimate procedures, protocol systems, or public services.

By August, there was no sign that the operation was winding down. A new wave used senders associated with the education sector in Amapá, a “certificate” ZIP hosted at marapoama[.]sp[.]gov[.]br, the CertificadoLeitorPCAP.exe loader, and yet another C2, eoplpfoepnwel[.]com.

New accounts. New files. New C2s. And the same cycle repeats once again.

September 2026: The Hosted Official Notice and search-ms

At the beginning of September, delivery still followed the pattern already seen in previous waves: @policiacivil.pe.gov.br and related email accounts, along with certificate-themed ZIPs and EXEs hosted on previpaulista[.]pe[.]gov[.]br and, once again, infrastructure in Marapoama.

Days later, the flow changed. The group began hosting the fraudulent document itself directly on a compromised .gov.br domain. The victim no longer depended solely on an attachment received by email. Upon accessing the address, they were presented with a page impersonating an official Civil Police notice, complete with visual elements designed to resemble an official communication, a document number, a request for banking information, and a button to “install digital certificate.”

Recent campaign (Sep/2026): fake official notice impersonating the Civil Police of Pernambuco, hosted at marapoama[.]sp[.]gov[.]br/documento, with a button prompting the victim to install a digital certificate.

In this wave, the PDF or link led to the search-ms: protocol. When clicked, it opened Windows Search pointing to a WebDAV share hosted on infrastructure belonging to the compromised municipality, at mail[.]marapoama[.]sp[.]gov[.]br. From there, the chain led the victim to a commercial RMM tool, Zoho Assist.

The lure remained the official notice. This time, however, the path to execution had changed.

The search-ms protocol used in the September 2026 campaign: Windows Search opens Suporte.lnk from mail.marapoama.sp.gov.br.

The messages were sent from multiple email accounts belonging to the same state, while the /documento path continued to be created individually for each target. Trust still came from compromised institutional infrastructure, but the directly downloaded executable was replaced by the use of a native Windows protocol, followed by remote access through an RMM tool.

The September campaigns also introduced two new C2 domains, policiacivilba[.]com and policiacivilpe[.]com. They follow the same lookalike pattern observed previously with policiacivilmg[.]com, pccvill[.]com, and pccvioo[.]com: .com domains designed to resemble Civil Police addresses, now referencing Bahia and Pernambuco.

The configuration observed on these hosts indicates that the infrastructure was being prepared for new waves of the campaign.

What Remained: BoostNote

While the infrastructure changed from one wave to the next, the Electron host remained largely unchanged. The filename, on the other hand, changed frequently.

In May 2026, the group moved away from the boost.exe observed in the previous wave and began persisting as draw.io.exe under %LOCALAPPDATA%\EasySuiteAutoTool\. In June, the same component reappeared as Boost Note.exe, this time under another fabricated directory, QuickPlusSmartPlusator. Later waves introduced names such as Grape.exe and App.exe.

Analysis of samples dating back to the February campaign reveals a relatively stable chain:

  1. Pre-stage: a PDF, QR code, or ClickFix flow leads the victim to the loader.
  2. Loader: an executable named after a certificate or official notice, compiled in Delphi and packaged with Inno Setup.
  3. Persistence: installation of a trojanized Electron host, which may appear as BoostNote, draw.io.exe, or another name. Observed paths include %LOCALAPPDATA%\ProSoftionTechMax\boost.exe, %LOCALAPPDATA%\EasySuiteAutoTool\draw.io.exe, and %LOCALAPPDATA%\QuickPlusSmartPlusator\Boost Note.exe. Other waves use directories with fabricated product-like names such as UltraSuiteSmartCoreware and ProSoftxUltraToolator.
  4. Beacon: the application’s index.js is deobfuscated, sends information about the workstation to the C2, and begins polling the server for new tasks.
  5. Next stages: the C2 can return JavaScript to be executed within the process through eval, or deliver an executable that is written to %TEMP% and launched on the workstation.

The original BoostNote is a legitimate Electron-based note-taking application. For the attacker, this choice offers several advantages. The process resembles productivity software, the installation directory looks like it belongs to a legitimate product, and C2 communication is hidden inside a common runtime.

In more recent builds, even the BoostNote name begins to disappear. The binary takes on generic names such as Grape.exe or App.exe and may be extracted into temporary is-*.tmp directories. The intent appears straightforward: change what defenders have learned to look for without abandoning what keeps the operation running.

It is the malicious index.js that persists across these changes. Once deobfuscated, the same logic repeatedly appears:

  • creates a persistent machine identifier under %APPDATA%;
  • reads a campaign or affiliate tag stored alongside the installer;
  • collects the computer and username;
  • establishes persistence through a Run key and setLoginItemSettings;
  • polls the C2 every few minutes for new tasks;
  • executes whatever it receives, whether a script or a binary.

Throughout 2026, redirectors, IP addresses, domains, and filenames changed frequently. The Electron host remained one of the most stable components of the operation. Once the workstation moves beyond the initial stage of compromise, what remains running is no longer the PDF, the official notice, or the page used as a lure. It is this core component that maintains communication with the group’s infrastructure and enables the delivery of subsequent stages.

For hunting, this distinction matters. Blocking Certificado_PCAP.exe may stop that week’s wave. Looking for ProSoftionTechMax, EasySuiteAutoTool, QuickPlusSmartPlusator, unexpected executions of boost.exe or draw.io.exe, Electron hosts loading an obfuscated index.js, and beacon patterns associated with the family allows defenders to hunt for the components the group continues to carry from one campaign to the next.

What Remained: The Backdoor Protocol

Domains and IP addresses are easy to replace in this operation. The protocol used by the beacon changes far less frequently.

Analysis of the samples revealed at least two generations of communication operating in parallel:

  1. GET generation. Requests to paths following the format /laravel.php?api=api&hash=<base64>&message=PT1n<base64>, with data sent directly through the query string.
  2. POST generation (more common). Requests to short paths, observed as /nbw/, /f/, /zta, and others, with a JSON body containing the machine identifier, COMPUTERNAME, USERNAME, and the tag associated with the campaign.

Despite the differences in communication, both generations share the same build chain involving Inno Setup, Electron, and index.js, as well as the same modular approach to delivering subsequent stages.

This is why simply blocking the domain only goes so far. The C2 used in one wave may be a Civil Police lookalike, such as policiacivilmg[.]com, while the next may use a completely random name such as dahieenloo[.]com or zsxocjarsate[.]com.

In some samples, the C2 observed during analysis no longer even corresponds to the infrastructure that was active during the campaign. The delivery infrastructure may remain hosted on a compromised .gov.br domain while the beacon points to infrastructure that has already been replaced.

Some of these C2s also sit behind Cloudflare, adding another layer between the observed domain and the origin infrastructure. For defenders, the more durable indicator is not the domain. It is how the malware communicates and the chain that brings it into execution. Analyzing beaconing patterns is essential to detecting this behavior.

What Changed: ClickFix

ClickFix was one of the major adaptations to the initial access flow following the Woovi campaign.

In February, the victim still had to open the PDF and click on the supposed certificate. It worked, but it followed a more traditional document-based phishing flow. ClickFix expanded the group’s initial access options:

  • the website could be hosted on an already compromised public-sector portal;
  • the page impersonated a routine verification process;
  • the requested action, opening Run with Win+R, pasting a command, and confirming, appeared to be part of the verification itself;
  • execution moved out of the browser and directly into the victim’s system.

The infrastructure supporting this flow also expanded. First came .gov.br and .jus.br portals. Later, dozens of compromised .com.br websites began serving as intermediary pages. For defenders, the specific domain quickly loses value. What remains is the sequence: apparently trusted infrastructure, a verification page, and execution performed by the victim.

Across several waves, ClickFix did not replace the official notice. It was added to the chain. The email led to the PDF. The PDF led to the website, in some cases through a QR code. The website then instructed the victim to execute the command. In other campaigns, the order changed, but the objective remained the same: move execution from the browser into Windows.

There was also a filtering stage along the way. Intermediary services evaluated visitors before delivering the malicious page. This allowed crawlers, sandboxes, and visitors of no interest to the operator to receive different content or simply never progress further into the chain. For a victim considered valid, the campaign continues. For automated analysis, it may look as if there is nothing there.

For our monitoring, this was one of the first clear indications that Shadow Ledger treats delivery as an adaptable part of the operation. When one path begins to lose effectiveness, another can take its place without requiring the rest of the chain to change.

What Changed: Official Notice Delivery

The official notice is one of the most consistent elements of the group’s social engineering. The way it is delivered is not.

Phase 1: The Official Notice as an Attachment

In the campaign associated with Woovi, the flow was still relatively straightforward: email, PDF, and then the supposed “certificate.” Credibility came primarily from the compromised institutional sender and the official appearance of the document.

Phase 2: The Official Notice as an Official Website

In the waves that followed, the group began to use compromised public-sector websites as part of the delivery chain. Email remained part of the operation, but victims were now directed to paths that appeared to belong to the portal itself:

  • /oficio
  • /oficio/*
  • /doc
  • /documento
  • /levantamento
  • /intermediacao
  • /procedimento
  • /protocolo

The /* matters here. There is not necessarily a single file or URL to block. Different subpaths within the same directory may lead to the same malware. In some campaigns, the path also included a unique identifier for each victim, making the address look like part of an individual case, protocol, or service request.

Phase 3: The Official Notice at Scale

By July and August 2026, the operation had expanded beyond the document itself. The group began operating with multiple compromised institutional email accounts, reusing mail administration panels and rotating senders across different Brazilian states.

By June, email subjects were already being generated in bulk, with the recipient’s name dynamically replaced using what was effectively a template. In July, we observed new accounts being created inside already compromised municipal email environments specifically for campaign distribution. After compromising a city’s email system, for example, the operators could create addresses resembling [email protected]. The legal language and institutional appearance remained.

In September 2026, the official notice no longer existed solely as an attachment or as a path leading to an .exe download. It was now presented as a page hosted directly on a compromised .gov.br domain, preserving the appearance of an official communication.

The next click used search-ms: to open Windows Search pointing to a WebDAV share hosted on the same compromised institutional infrastructure. In this wave, the next stage we observed led to a commercial RMM tool, Zoho Assist, rather than the same Electron loader seen in previous campaigns.

This evolution helps close the loop described at the beginning of this post. Compromising a .gov.br domain does not simply mean gaining control of a website. For the group, that access can provide:

  • a place to host the payload or the official notice itself;
  • a trusted domain that can help bypass filters and reduce suspicion;
  • email accounts and, in some cases, WebDAV infrastructure to extend the chain;
  • an institutional identity that makes the approach significantly more convincing.

For that reason, official notice delivery may be the clearest example of how Shadow Ledger evolved throughout 2026. The lure remained the same, but the way it was delivered kept evolving. The C2 server, binary name, hashes, domain, path, and even the mechanism triggered by the click can change without changing the operation’s underlying objective.

When Initial Access Meets a Permissive Environment

Phishing explains how the attacker gets in, but it does not, by itself, explain why that access can go so far.

Across our Incident Response engagements and the analyses conducted throughout our monitoring, we identified another recurring factor: security controls that unnecessarily expanded the attack surface available after a workstation or identity had been compromised.

This appeared in several forms.

Back-office systems directly exposed to the Internet. Administrative panels and internal systems were externally accessible without a clear operational need or without an additional layer of access control. For an operator who has just obtained a valid corporate session, finding this type of application significantly shortens the path between initial compromise and a sensitive system.

Pix-related artifacts stored on hosts where they did not need to be. In some environments, we found files and certificates used in validation and integration processes related to cash-in and cash-out flows stored on workstations or servers without a clear operational justification. The problem is not simply that the file exists. It is the value that host gains once it is compromised.

Users with more privileges than necessary. Accounts used for day-to-day activities retained access to systems, administrative panels, and functions that were not required for those activities. When that user’s session is stolen, the attacker inherits part of that access surface.

Sensitive sessions concentrated on the same workstation. Corporate email, administrative panels, financial platforms, and other systems remained authenticated within the same browser. In this scenario, compromising the endpoint no longer means gaining access to a single application. It means taking over an identity that already has open paths into different parts of the operation.

None of these issues, in isolation, explains the success of Shadow Ledger. The problem emerges when they come together.

A phishing campaign does not need to end in the exploitation of a critical vulnerability when the compromised identity can already reach critical systems directly.

This is where security maturity makes a difference. Segmenting back-office systems, restricting external exposure, enforcing least privilege, properly protecting certificates and other sensitive artifacts, and reducing the concentration of privileged sessions will not stop the official notice from reaching the inbox, but they can drastically reduce what the attacker is able to do after the initial compromise.

What This Case Teaches Us

Shadow Ledger shows that an operation does not need a zero-day to be effective. Persistence, scale, and the ability to adapt can be enough.

After a year of monitoring, several lessons stand out:

  • A public incident does not represent the entire campaign. Woovi made the pattern visible, but the operation already existed before that incident and continued to appear across other organizations in the months that followed.
  • An official sender does not mean a safe sender. A genuinely compromised institutional account can pass SPF, DKIM, and DMARC checks while carrying a level of credibility that an unknown domain would struggle to achieve.
  • The official notice works because it exploits trust that already exists. Police communications, summons, legal proceedings, powers of attorney, and certificates are not chosen at random. They are the kinds of communications that naturally create attention and urgency.
  • IoCs rotate. TTPs last longer. From June onward, nearly every new wave introduced a different C2. The Electron chain, ClickFix, the use of search-ms:, paths such as /oficio, and the beacon’s communication patterns provide more durable correlation points than the IP address or domain used in a single campaign.
  • Compromised public-sector websites become campaign infrastructure. Municipal governments, city councils, public pension funds, and protocol portals are turned into hosts for documents, pages, and payloads. In many cases, the government organization is not the final target. It is part of the path to it.
  • Stealing a session changes the authentication problem. With an already authenticated session in hand, the operator can reuse that access without necessarily going through the login flow and MFA challenge again.
  • A “clean” sample does not end the investigation. An Inno installer, an Electron host, or an institutional notice may appear relatively unremarkable when analyzed in isolation. It is the correlation between them that reveals the campaign.
  • IR and CTI ultimately look at the same pieces from different perspectives. The official notice seen during monitoring is the same one that later reappears on the endpoint. The C2 identified through intelligence supports hunting. And the artifact recovered during Incident Response helps explain the next wave.

None of this depends on a sophisticated operation in the cinematic sense. It depends on time, scale, repetition, and adaptation. Shadow Ledger found a way to exploit not only technical vulnerabilities, but something much harder to block: the trust that companies and people place in legitimate institutions.

Conclusion

The Woovi case was the moment Shadow Ledger gained public visibility. For our monitoring, it was the point when an operation that had already been active began to reveal a much broader pattern.

Nearly a year later, the operation remains recognizable by the same elements: trust in official communications, an adaptable delivery infrastructure, and the recurring use of Electron for persistence. What changed was how the group reached its victims. ClickFix, new C2s with each wave, draw.io.exe replacing boost.exe, official notices hosted on .gov.br domains, search-ms:, and commercial RMM tools have made the operation much harder to contain with a single block.

Woovi was not an isolated incident. The same cycle resurfaced across several other organizations and relied on dozens of public-sector assets as part of its delivery infrastructure. As long as official communications carry trust by default, that trust will continue to be exploited as part of the attack.

At QuimeraX, this kind of monitoring is about going beyond what happened on the day of the incident. The goal is to understand how the operation continues after the headlines have faded, which components the group keeps, which ones it replaces, and where defenders may still be looking for last week’s domain, IP address, or file while the underlying behavior remains largely unchanged.

More than the story of a single incident, Shadow Ledger reinforces a simple idea: in Brazil, institutional trust still functions as a security control. We trust the domain, the sender, the document, and the appearance of an official communication. The group has learned to exploit exactly that.

When that trust is compromised, the attacker no longer needs to look legitimate. They are already operating from infrastructure that is.

Want the QuimeraX team monitoring threats that could affect your organization?
Request a demo and see QuimeraX in action: https://quimerax.com

Useful Indicators for Hunting

The list below is intentionally short. Shadow Ledger’s infrastructure changes frequently, so extensive lists of domains and IP addresses quickly become outdated.

For hunting, it is more valuable to start with the elements that survive infrastructure changes.

AnchorWhat to Look For
Electron persistence%LOCALAPPDATA%\ProSoftionTechMax\boost.exe, %LOCALAPPDATA%\EasySuiteAutoTool\draw.io.exe, %LOCALAPPDATA%\QuickPlusSmartPlusator\Boost Note.exe, as well as Grape.exe and App.exe under temporary is-*.tmp directories
Build chainDelphi + Inno Setup installer loading a Node.js/Electron application with an obfuscated index.js
Loader / official noticeExecutables with names such as Certificado_*, Oficio*, Intimacao*, Requerimento*, Procuracao*, and DocumentoPC*, as well as documents such as Ofc.pdf
GET beaconRequests to /laravel.php?api=api&hash= accompanied by message=PT1n
POST beaconPOST /nbw/ containing a machine identifier, COMPUTERNAME, and USERNAME
ClickFix / search-msSequences involving Win+R followed by command pasting, a QR code embedded in a PDF, or a search-ms: URI pointing to WebDAV and files such as Suporte.lnk
Malicious extensionAn extension installed outside the Chrome Web Store, presented as an SSL certificate or security component, with cookies and <all_urls> permissions
Institutional deliveryPaths such as /oficio, /doc, /documento, /levantamento, /intermediacao, and /arquivofiscal serving executables, ZIP files, or official notice pages
Institutional email.gov.br or .jus.br senders combined with official notices, summons, or certificate-themed content, including messages that pass SPF, DKIM, and DMARC checks
Post-compromise activityUnauthorized or unapproved RMM tools such as MasterRemote, MeshCentral, AnyDesk, or Zoho Assist, particularly on workstations used by users with administrative or financial access

The names used for persistence varied between boost.exe, draw.io.exe, Boost Note.exe, Grape.exe, and App.exe, while the operation also abused different commercial remote access tools.

Historical IoCs

The list below consolidates IoCs observed between September 2025 and September 2026 while tracking Shadow Ledger activity.

The group’s infrastructure changes frequently. For this reason, these indicators should be used primarily for retrospective hunting, correlation, and investigation enrichment, rather than as a permanent blocklist. All network indicators are presented in defanged form.

Network: IP Addresses

The addresses below were associated, at different points in the operation, with infrastructure used for C2, redirection, payload distribution, stealers, and campaign delivery.

IndicatorObserved RolePeriod
79[.]110[.]49[.]32Redirector / hosting (80, 443, 3389)Feb 2026
79[.]110[.]49[.]5Redirector, successor to .32Feb 2026
79[.]110[.]49[.]43Redirector / stealer, with AnyDesk on port 7070Feb–Mar 2026
195[.]177[.]94[.]94C2 / stealer associated with kapa[.]is and info[.]kak[.]is (3333, 3334, 8888)Feb–Mar 2026
195[.]177[.]94[.]103Backend associated with the official notice armJan–Jul 2026
195[.]177[.]94[.]148C2Mar 2026
195[.]177[.]94[.]14kak[.]is backend associated with the extension (443)Mar 2026
195[.]177[.]94[.]64kak[.]is backend associated with the extension (80)Mar 2026
94[.]154[.]32[.]112Stealer (3003, 3004, 3005)Feb–Mar 2026
91[.]92[.]243[.]207Origin C2 associated with jmkkload[.]com, protected by CloudflareMar 2026
91[.]92[.]241[.]181C2 associated with oficiospolicia[.]comApr 2026
185[.]219[.]83[.]191Electron backdoor beaconJul 2026
188[.]137[.]246[.]189Beacon / associated C22026
179[.]43[.]182[.]27Management / aggregation hostMar 2026
179[.]43[.]167[.]210Stealer (3333, 3334)Apr 2026
194[.]59[.]30[.]191Backend for .js scriptsApr 2026
200[.]189[.]123[.]155SMTP server used in campaign (smtp01[.]pr[.]gov[.]br)Mar 2026
104[.]249[.]10[.]245Delivery redirectorMar 2026
132[.]148[.]180[.]83ClickFix infrastructure associated with compracertanfe[.]comMay 2026
94[.]154[.]32[.]35Payload distribution via /d/out.txtMay 2026
158[.]94[.]208[.]120C2 associated with policiacivilmg[.]comMay 2026
195[.]177[.]94[.]62Associated C2May 2026

Network: C2 Domains and Campaign Infrastructure

The domains below were observed serving different roles within the operation, including C2, exfiltration, payload distribution, ClickFix, malicious extension infrastructure, and redirection.

They are listed separately from compromised institutional domains, such as .gov.br and .jus.br, which the group used as delivery infrastructure.

IndicatorObserved Role
kapa[.]isC2 / beacon (/f/e/)
kak[.]isC2 / stealer / extension
xx[.]kak[.]isClickFix catalog / payload distribution
yy[.]kak[.]isClickFix catalog
info[.]kak[.]isExfiltration (3333, 3334, 8888)
goingg[.]isC2 associated with the extension
ext[.]kak[.]isExtension panel, earlier infrastructure
ext[.]goingg[.]isExtension panel, later infrastructure
jmkkload[.]comC2 protected by Cloudflare
oficiospolicia[.]comC2 panel
policiacivilmg[.]comPolice-themed C2
pccvill[.]comPolice-themed C2
pccvioo[.]comPolice-themed C2
policiacivilba[.]comPolice-themed C2, referencing Bahia
policiacivilpe[.]comPolice-themed C2, referencing Pernambuco
dahieenloo[.]comRandomly named C2
psznaoehteeh[.]comRandomly named C2
eeresofeuae[.]comRandomly named C2
zsxocjarsate[.]comC2 associated with POST /nbw/ beaconing
taaeiuep[.]comC2 associated with the Inno / digital power of attorney chain
api[.]sessionvalidator[.]comTasking framework
compliancemetrics[.]netTasking framework
oauth[.]openvpnet[.]comAssociated C2
conformidade[.]certificadosoficiais[.]comRedirector using a ZeroSSL certificate
antiddos-protection[.]netCampaign infrastructure
compracertanfe[.]comClickFix infrastructure
checkeronlinehuman[.]comInfrastructure associated with the judicial-themed wave
eoplpfoepnwel[.]comC2 observed in Aug 2026

Delivery, C2, and Associated Infrastructure URLs

The URLs below were observed at different stages of the campaigns, including redirection, payload delivery, ClickFix, C2 communication, extension distribution, and abuse of compromised institutional infrastructure.

The presence of a .gov.br domain in this table represents a historical observation of abuse or compromise during the campaign. It does not mean that the asset remains compromised today and should not be interpreted as a recommendation to block the institutional domain.

IndicatorObserved Context
hxxps://79[.]110[.]49[.]32/.certificados.ap.gov.brRedirector used in the campaign associated with Woovi
hxxps://kapa[.]is/f/e/BoostNote beacon / C2
hxxp://<c2>/laravel.php?api=api&hash=GET beacon pattern observed in the earlier generation
hxxps://zsxocjarsate[.]com/nbw/POST beacon observed in 2026
hxxps://kak[.]is/pipiteimosa.extension.jsScript associated with the stealer / extension
hxxps://kak[.]is/te_3_la.jsAdditional script associated with the stealer
hxxps://kak[.]is/urlzzz.phpCampaign endpoint
hxxps://kak[.]is/__________________________/chrome_extension.zipExtension package distribution
hxxps://kak[.]is/temp/WinPython/preto.pyAuxiliary artifact
hxxps://xx[.]kak[.]is/_verosss_/russo.exePayload distribution
hxxps://xx[.]kak[.]is/1.txtCatalog associated with ClickFix
hxxps://yy[.]kak[.]is/1.txtCatalog associated with ClickFix
hxxps://xx[.]kak[.]is/_clkfx/lnk1.txtClickFix catalog, Apr 2026
hxxps://goingg[.]is/whitelist.extension.txtDynamic extension configuration
hxxps://goingg[.]is/pipiteimosa.extension.jsRemote extension payload
hxxps://ext[.]kak[.]is/Panel associated with the extension
hxxps://ext[.]goingg[.]is/Later panel associated with the extension
hxxps://jmkkload[.]com/C2
hxxps://cmdca[.]go[.]gov[.]br/downloadClickFix / MasterRemote delivery
hxxps://conseg[.]ssp[.]go[.]gov[.]br/COAF-POLICIAFEDERAL.exeExecutable hosted on compromised .gov.br infrastructure
hxxps://prodoc[.]ap[.]gov[.]brClickFix / official notice
hxxps://timon[.]ma[.]gov[.]brDelivery infrastructure shared between the official notice and installer chains
hxxps://protocolo[.]sorocaba[.]sp[.]gov[.]brDelivery infrastructure shared between the official notice and installer chains
hxxps://cee[.]rr[.]gov[.]br/oficioOfficial notice delivery
hxxps://sistemas[.]cabo[.]pe[.]gov[.]br/oficio.phpOfficial notice delivery
hxxps://sg[.]plantaalagoas[.]al[.]gov[.]br/oficiosOfficial notice delivery
hxxps://efis[.]sipom[.]pm[.]ms[.]gov[.]br/oficio/Official notice delivery
hxxps://sisct[.]cidadania[.]gov[.]br/comunidades-web/baixar.jspAssociated delivery infrastructure
hxxps://ibrep[.]alfamaoraculo[.]com[.]br/core/components/Certificado_Pcap.exeDropper / MasterRemote
hxxp://previpaulista[.]pe[.]gov[.]br/oficio/*IntimacaoPCAP.exe delivery
hxxps://camaraparaguacu[.]sp[.]gov[.]br/doc/*RequerimentoPC.exe delivery
hxxps://camaraparaguacu[.]sp[.]gov[.]br/intermediacaoRequerimentoPC.exe delivery
hxxps://camaraparaguacu[.]sp[.]gov[.]br/oficioRequerimentoPC.exe delivery
hxxps://floresdegoias[.]go[.]gov[.]br/levantamentoNotificacaoPCPE.exe delivery
hxxps://areal[.]rj[.]gov[.]br/levantamento/*ProcuracaoDigital.exe delivery, with a victim-specific path
hxxps://prefeituradepoa[.]sp[.]gov[.]br/docDelivery observed on Jul 13, 2026
hxxps://funrespol[.]pc[.]ro[.]gov[.]br/documentoDelivery observed on Jul 13, 2026
hxxps://funprecon[.]pe[.]gov[.]br/arquivos/extension.zipExtension package hosted on compromised .gov.br infrastructure
hxxps://funprecon[.]pe[.]gov[.]br/ys.php?p=Tiny File Manager observed on compromised infrastructure
hxxps://www[.]funrespol[.]pc[.]ro[.]gov[.]br/anexos_evento/uploads/fm.phpFile manager observed on compromised infrastructure
hxxps://dipol[.]policiacivil[.]sp[.]gov[.]br/conferirviatura/imagens/2e39069c345e175af74a031a2d9523a7.phpWeb shell observed on compromised infrastructure
hxxp://94[.]154[.]32[.]35/d/out.txtPayload distribution, May 2026
hxxps://poa[.]sp[.]gov[.]br/arquivofiscal/tboKmG/dDvBqCDocumentoPCPE.exe delivery, May 2026
hxxps://aquisicoes[.]seplag[.]mt[.]gov[.]br/sigacontrato/subsystems/comum/signkit.jsp?yd=Delivery associated with the judicial-themed wave, Jun 2026
hxxps://dd[.]checkeronlinehuman[.]com/static/js/dashboard.runtime.jsScript associated with the judicial-themed wave, Jun 2026
hxxps://dd[.]checkeronlinehuman[.]com/v2/agents/registerAgent registration observed in the judicial-themed wave, Jun 2026
hxxps://areal[.]rj[.]gov[.]br/levantamento/5gr67jExample of a victim-specific path
hxxps://camaraparaguacu[.]sp[.]gov[.]br/doc/kdkddlDelivery observed in Jun 2026
hxxps://dahieenloo[.]com/C2 observed in Jun 2026
hxxp://sigdoc[.]ap[.]gov[.]br/public/verArquivo[.]jsfDelivery observed in Aug 2026
hxxp://marapoama[.]sp[.]gov[.]br/CertificadoPCAP[.]zipCertificate-themed ZIP, Aug 2026
hxxps://previpaulista[.]pe[.]gov[.]br/oficio/*/*Delivery pattern observed in Sep 2026
hxxps://marapoama[.]sp[.]gov[.]br/CertificadoPCPE.zipCertificate-themed ZIP, Sep 2026
hxxps://marapoama[.]sp[.]gov[.]br/documentoOfficial notice hosted directly on the compromised portal, Sep 2026
hxxps://marapoama[.]sp[.]gov[.]br/documento/*/*Target-specific path, Sep 2026
search-ms:query=Suporte.lnk&crumb=location:\\\mail[.]marapoama[.]sp[.]gov[.]br\DavWWWRootWindows Search pointing to WebDAV, Sep 2026
hxxps://eoplpfoepnwel[.]com/C2 observed in Aug 2026
hxxps://policiacivilba[.]com/Police-themed C2 observed in Sep 2026
hxxps://policiacivilpe[.]com/Police-themed C2 observed in Sep 2026
assist[.]zoho[.]comZoho Assist observed as an RMM tool in the search-ms: wave, Sep 2026

Files, Hashes, and Persistence Artifacts

The artifacts below were observed across different waves of the operation and include loaders, documents, Electron chain components, extension packages, and files used for persistence.

Hashes are presented as historical indicators. Filenames, on the other hand, should be correlated with paths, behavior, and other signals from the chain, as they may change between campaigns.

FileHashObserved Context
Certificado_PCAP.exeMD5 05d8c7d4bc49a2da4587535abae9b06dLoader, Feb 2026
Sample with no preserved filenameMD5 8bd9f1e7a0b11a0a08c1205983412286Campaign sample, Mar 2026
Sample with no preserved filenameSHA256 e81c9825936156152f52ab17caae50cd5a457c58ea714880629f5dcd2637c9cfSame sample, Mar 2026
IntimacaoPCAP.exeMD5 998c57f34bbfdbd71c39e05756c9845dDelivery via .gov.br
IntimacaoPCAP.exeSHA1 785575764c27ed7c86084286f7470b6bed86b9ebSame sample
IntimacaoPCAP.exeSHA256 3ca047f71d398a05894163ccb0fe385583329805b370d7e9396f32187facd8a9Same sample
RequerimentoPC.exeMD5 98d1e966010f88e0bf26f414f2f0f55aLoader / delivery
RequerimentoPC.exeSHA1 ea18659fa43b9005b85eb7bc788dc7fedd2f9f8bSame sample
RequerimentoPC.exeSHA256 8b3f0c4984c5448977c3e7e8330504b949a1c4fc47772697ceb07beb4710b87dSame sample
NotificacaoPCPE.exeMD5 145888cca508ed7333317097d03fde32Loader / delivery
NotificacaoPCPE.exeSHA1 16a9e74ac547e1ddd616e2022131fd78e0ab5d3eSame sample
NotificacaoPCPE.exeSHA256 9832843da2c6057bd8a522820b947e507b1c5560f07c3449ba917592efd5439fSame sample
ProcuracaoDigital.exeMD5 3dbd4dbbe24685648ca5ae7e751cef46Loader / delivery
ProcuracaoDigital.exeSHA1 f5858f1a4afc204841ed284117b99fa3c7f447eeSame sample
ProcuracaoDigital.exeSHA256 ebaf5aded88ec40f16f1448586633ff44d907abb2d8990cb52ba7f6a6e405831Same sample
OficioPC.exeMD5 c4d6bc8a0dc4f9df9021c2311dbb1056Same operational family
OficioPC.exeSHA1 7320857bc6c2dd69a44b602fc298d4af472cb246Same sample
OficioPC.exeSHA256 47786e32b166bc027ace509daf3ecd8253ebf2cbe2de32926529005fc03d374fSame sample
Procuracao_Digital.exeMD5 15801b64c170752caaf1fa329f946382Loader / delivery
Procuracao_Digital.exeSHA1 ddeb7b9b6bf4e88544ef0576c74726805148d4feSame sample
Procuracao_Digital.exeSHA256 e0dae1a04b7a3b2ae07377b0fd00681e9633532788870b3709a9e149f3ccf0e0Same sample
index.jsSHA256 71f69978667dc421e7edf8885e9f3bde9dd527d9f7974228c9a6eac84c2ab71cElectron host backdoor
DocumentoPCPE.exe / draw.io.exeMD5 e02e55554ea7f50a9da7bbd7fb48fdf9EasySuiteAutoTool persistence, May 2026
DocumentoPCPE.exe / draw.io.exeSHA256 6dc6d269b5c5c717d7ac06f7305b7362f22742c87e77049c1670bae3c8e18560Same sample
Sample with no preserved filenameMD5 20896fdc683273d4d5575b8d932ddc5aJudicial-themed wave, Jun 2026
Sample with no preserved filenameSHA1 a90d804c4e7b651d29abd787a267020cba44e272Same sample
Sample with no preserved filenameSHA256 bfc632e5040adbec76ae73c182be3910fc314bde743ca2a69c2a0c8e95c0fdc2Same sample
Ofc.pdfMD5 91349675b6a5ad547babe05121da98d4Official notice, Aug 2026
Ofc.pdfSHA1 e3075bce3897a48a0e46b8314688251297dc4a06Same sample
Ofc.pdfSHA256 333c60dd1c4e54d0700b91a666f8588f3c8b2639d82dee7e2454f8e0881eb860Same sample
CertificadoLeitorPCAP.exe / CertificadoPCPE.exeMD5 f76e7b97a0589a1965d734b669afed40Loader, Aug–Sep 2026
CertificadoLeitorPCAP.exe / CertificadoPCPE.exeSHA1 54791e8b81719a81771a19ac3a87832ea2ad56c9Same sample
CertificadoLeitorPCAP.exe / CertificadoPCPE.exeSHA256 8ccfbc26fee9c4fd20566abfbb43587334e1060a65f4027eb957c34761250199Same sample
CertificadoPCPE.zipMD5 323168687c4ec30a6b54cc700f457962Package, Sep 2026
CertificadoPCPE.zipSHA1 ba75d2760d552d70d4ac49afbea9b8603a541cc5Same package
CertificadoPCPE.zipSHA256 1160ab6ef017a9bf2d02a6401883741cefd6fd3fbe0c2da464a9f1f818f08c8eSame package

Persistence, Extension, and Remote Access Tools

In addition to hashes, several endpoint artifacts remained useful for hunting even as the infrastructure and sample names changed.

IndicatorObserved Context
%LOCALAPPDATA%\ProSoftionTechMax\boost.exeTrojanized BoostNote host
%LOCALAPPDATA%\EasySuiteAutoTool\draw.io.exeAlternative persistence, May 2026
%LOCALAPPDATA%\QuickPlusSmartPlusator\Boost Note.exePersistence observed in Jun 2026
%APPDATA%\setup.txtAuxiliary artifact associated with the draw.io.exe wave
Grape.exe / App.exeRenamed Electron binary
UltraSuiteSmartCoreware / ProSoftxUltraToolatorInstallation directories with fabricated product-like names
setLoginItemSettings + Run keyPersistence mechanisms observed in index.js
Certificado SSL ChormeName observed in the malicious MV3 extension
extension.zipExtension package hosted on compromised .gov.br infrastructure
cookies + <all_urls>Permissions observed in the extension
MasterRemoteRMM observed as a subsequent stage
ScreenConnectRMM observed as a subsequent stage
MeshCentralRMM observed as a subsequent stage
AnyDeskAdditional RMM, including a service observed on port 7070
Zoho Assist (assist[.]zoho[.]com)RMM observed in the search-ms: wave, Sep 2026

Observed Institutional Senders

The accounts and domains below were observed as delivery channels in different campaigns associated with Shadow Ledger. In several cases, the messages originated from compromised legitimate institutional infrastructure, allowing the email to retain characteristics expected of authentic communications.

The presence of an address or domain in this table represents a historical observation. It does not mean that the account, user, or institution remains compromised today and should not be interpreted as a recommendation to block the domain.

IndicatorObserved Context
@policiacivil[.]ap[.]gov[.]brSending domain observed in the campaign associated with Woovi and in subsequent waves
deccon[@]policiacivil[.]ap[.]gov[.]brSender observed in Feb 2026
deiai[@]policiacivil[.]ap[.]gov[.]brSender observed in Feb 2026
@pc[.]es[.]gov[.]brDomain used to send PDFs
wagno[.]manguinhos[@]pc[.]es[.]gov[.]brSender used to deliver PDFs
@pcivil[.]rj[.]gov[.]brDomain used to send PDFs
@pc[.]sp[.]gov[.]brDomain used to send PDFs
@pr[.]gov[.]brDomain observed in the Paraná wave, involving different government agencies
smtp01[.]pr[.]gov[.]brSMTP server observed in the Paraná wave
@sesp[.]es[.]gov[.]brDomain used to send PDFs
loginam[.]sesp[.]es[.]gov[.]brAsset associated with the campaign
policiacivil[@]ituporanga[.]sc[.]gov[.]brSender used to deliver PDFs
alinesouza[.]guaira[@]pr[.]gov[.]brSender used to deliver PDFs
willian[.]kesseli[@]appa[.]pr[.]gov[.]brSender used to deliver PDFs
luisgregorini[@]der[.]pr[.]gov[.]brSender used to deliver PDFs
rebjuliocesar[@]seed[.]pr[.]gov[.]brSender used to deliver PDFs
mariaalzenir[@]idr[.]pr[.]gov[.]brSender used to deliver PDFs
urbanismo[@]quatrobarras[.]pr[.]gov[.]brSender used to deliver PDFs
anabreda[@]seed[.]pr[.]gov[.]brSender used to deliver PDFs
cartorioprocon[@]cascavel[.]pr[.]gov[.]brSender used to deliver PDFs
policacivil[@]cravinhos[.]sp[.]gov[.]brSender observed in May 2026, using a narrative related to the Civil Police of Rio Grande do Norte (PC/RN)
juan[.]cartacho[@]sejus[.]es[.]gov[.]brSender observed in May 2026
jose[.]azevedo[@]pc[.]pb[.]gov[.]brSender observed in May 2026
jose[.]luzia[@]policiacivil[.]pe[.]gov[.]brSender observed in May 2026
contato[@]tjto[.]jus[.]brSender associated with the judicial-themed wave, Jun 2026
gpequeno[@]mprj[.]rj[.]brSender observed in Jun 2026
antonio[.]pereira[@]ipa[.]brSender observed in Jun 2026
antonio[.]pereira[@]pm[.]pe[.]gov[.]brSender observed in Jun 2026
*[@]ipa[.]br / *[@]pm[.]pe[.]gov[.]brSending domains observed in Jun 2026
ana[.]paula[.]silva[@]sjdh[.]pe[.]gov[.]brSender observed in Jun 2026
rogerio[.]lima[@]seap[.]pe[.]gov[.]brSender observed in Jun 2026
policia[.]civil[@]itaipulandia[.]pr[.]gov[.]brSender observed in Jul 2026
delegadomarcost*[@]itaipulandia[.]pr[.]gov[.]brMailbox naming pattern observed in Jul 2026 campaign activity
cpvpeb[@]seed[.]ap[.]gov[.]brSender observed in Aug 2026
ncc[@]seed[.]ap[.]gov[.]brSender observed in Aug 2026
ivson[.]felix[@]corregedoria[.]sds[.]pe[.]gov[.]brSender observed in Sep 2026
*[@]corregedoria[.]sds[.]pe[.]gov[.]brSending domain observed in Sep 2026
ivson[.]felix[@]policiacivil[.]pe[.]gov[.]brSender observed in Sep 2026
*[@]policiacivil[.]pe[.]gov[.]brSending domain observed in Sep 2026

ClickFix Intermediary Sites

In addition to institutional infrastructure, a wave observed in April 2026 used several .com.br websites as intermediary pages in the ClickFix chain.

As with the government assets, these are historical indicators of abuse observed during the investigation. The presence of a domain in this list does not mean that the website remains compromised today.

Indicator
www[.]dragermanasilvestri[.]com[.]br
www[.]acpunica[.]com[.]br
assistancesolucoesabc[.]com[.]br
belices[.]com[.]br
brumalucelli[.]com[.]br
carolinaterapiaintegrativa[.]com[.]br
biofur[.]com[.]br
chegoupagou[.]com[.]br
concursosresultado[.]com[.]br
www[.]jddev[.]com[.]br
www[.]mstortti[.]com[.]br
www[.]redesindicos[.]com[.]br
www[.]netlm[.]com[.]br
www[.]refricorpos[.]com[.]br
www[.]resultfacil[.]com[.]br
www[.]talkhere[.]com[.]br
www[.]totalservicosadm[.]com[.]br
www[.]transguiterraplanagem[.]com[.]br
www[.]vocefaznfe[.]com[.]br
www[.]vivendadolago[.]com[.]br
plataformajacitraining[.]com[.]br
www[.]wmempresas[.]com[.]br
osnirestevam[.]com[.]br
slamdigital[.]com[.]br
www[.]beefpassion[.]com[.]br
ebinterchange[.]com[.]br

Compromised Institutional Infrastructure

Throughout the investigation, we identified a significant number of compromised municipal, state-level, and other institutional assets associated with Shadow Ledger campaigns.

These assets appeared in different roles, including payload hosting, official notice pages, ClickFix, extension distribution, and other components of the delivery chain. In some cases, the same infrastructure was reused across different waves of the operation.

The list below is not exhaustive and represents historical observations. The presence of a domain does not mean that the asset remains compromised today and should not be interpreted as a recommendation to block the institutional domain.

StateObserved Domains
ALchapreta[.]al[.]gov[.]br, sg[.]plantaalagoas[.]al[.]gov[.]br
APprodoc[.]ap[.]gov[.]br, sigdoc[.]ap[.]gov[.]br, seed[.]ap[.]gov[.]br
BAgaviao[.]ba[.]gov[.]br, itiuba[.]ba[.]gov[.]br
ESloginam[.]sesp[.]es[.]gov[.]br, sejus[.]es[.]gov[.]br
GOcamaravalparaiso[.]go[.]gov[.]br, cmvg[.]go[.]gov[.]br, floresdegoias[.]go[.]gov[.]br, jataiprevi[.]go[.]gov[.]br, simolandia[.]go[.]gov[.]br, cmdca[.]go[.]gov[.]br, conseg[.]ssp[.]go[.]gov[.]br
MAtimon[.]ma[.]gov[.]br, candidomendes[.]ma[.]gov[.]br, centraldomaranhao[.]ma[.]gov[.]br, cmarari[.]ma[.]gov[.]br, cmcentraldomaranhao[.]ma[.]gov[.]br, cmigarapegrande[.]ma[.]gov[.]br, cmlagodosrodrigues[.]ma[.]gov[.]br, cmmarajadosena[.]ma[.]gov[.]br, cmpauloramos[.]ma[.]gov[.]br, cmpocaodepedras[.]ma[.]gov[.]br, cmpresidentesarney[.]ma[.]gov[.]br, cmsantaines[.]ma[.]gov[.]br, cmsaoraimundododocabezerra[.]ma[.]gov[.]br, cmvitorinofreire[.]ma[.]gov[.]br, conceicaodolagoacu[.]ma[.]gov[.]br, governadorarcher[.]ma[.]gov[.]br, jenipapodosvieiras[.]ma[.]gov[.]br, mataroma[.]ma[.]gov[.]br, palmeirandia[.]ma[.]gov[.]br, presidentemedici[.]ma[.]gov[.]br, saobeneditodoriopreto[.]ma[.]gov[.]br, tufilandia[.]ma[.]gov[.]br, vitorinofreire[.]ma[.]gov[.]br
MGcamaradelassance[.]mg[.]gov[.]br, camaradouradoquara[.]mg[.]gov[.]br, camaraestreladosul[.]mg[.]gov[.]br, camaralontra[.]mg[.]gov[.]br, camaravarginha[.]mg[.]gov[.]br, cascalhorico[.]mg[.]gov[.]br, douradoquara[.]mg[.]gov[.]br, estreladosul[.]mg[.]gov[.]br, lontra[.]mg[.]gov[.]br, previlagoa[.]mg[.]gov[.]br, saojoaodamata[.]mg[.]gov[.]br, uniprevdivino[.]mg[.]gov[.]br
MStreslagoasprevidencia[.]ms[.]gov[.]br, efis[.]sipom[.]pm[.]ms[.]gov[.]br
MTseplag[.]mt[.]gov[.]br, aplicacao[.]cbm[.]mt[.]gov[.]br
PBcamaradecacimbadedentro[.]pb[.]gov[.]br, camarapedralavrada[.]pb[.]gov[.]br, pc[.]pb[.]gov[.]br
PEfunprecon[.]pe[.]gov[.]br, previpaulista[.]pe[.]gov[.]br, sistemas[.]cabo[.]pe[.]gov[.]br, policiacivil[.]pe[.]gov[.]br, sjdh[.]pe[.]gov[.]br, seap[.]pe[.]gov[.]br, corregedoria[.]sds[.]pe[.]gov[.]br
PIcamaramunicipaldesaofranciscodopiaui[.]pi[.]gov[.]br
PRanahy[.]pr[.]gov[.]br, brasilandiadosul[.]pr[.]gov[.]br, cidelparna[.]pr[.]gov[.]br, cmperobal[.]pr[.]gov[.]br, farol[.]pr[.]gov[.]br, novalaranjeiras[.]pr[.]gov[.]br, quatropontes[.]pr[.]gov[.]br, tuneirasdooeste[.]pr[.]gov[.]br, itaipulandia[.]pr[.]gov[.]br
RJareal[.]rj[.]gov[.]br, prevsul[.]rj[.]gov[.]br
ROfunrespol[.]pc[.]ro[.]gov[.]br
RRbonfim[.]rr[.]gov[.]br, canta[.]rr[.]gov[.]br, uiramuta[.]rr[.]gov[.]br, cee[.]rr[.]gov[.]br
RSamaralferrador[.]rs[.]gov[.]br, camaraamaralferrador[.]rs[.]gov[.]br, camaraeldorado[.]rs[.]gov[.]br, camaranovapalma[.]rs[.]gov[.]br, camarapinhalgrande[.]rs[.]gov[.]br, camarasantamargaridadosul[.]rs[.]gov[.]br, circ[.]rs[.]gov[.]br, cmfaxinaldosoturno[.]rs[.]gov[.]br, cmvdonafrancisca[.]rs[.]gov[.]br, donafrancisca[.]rs[.]gov[.]br, faxinaldosoturno[.]rs[.]gov[.]br, ivora[.]rs[.]gov[.]br, jari[.]rs[.]gov[.]br, novapalma[.]rs[.]gov[.]br, pinhalgrande[.]rs[.]gov[.]br, restingaseca[.]rs[.]gov[.]br, xangrila[.]rs[.]gov[.]br
SPcamaraparaguacu[.]sp[.]gov[.]br, cmauriflama[.]sp[.]gov[.]br, cmnovacastilho[.]sp[.]gov[.]br, condemat[.]sp[.]gov[.]br, ferrazdevasconcelos[.]sp[.]gov[.]br, marapoama[.]sp[.]gov[.]br, mail[.]marapoama[.]sp[.]gov[.]br, prefeituradepoa[.]sp[.]gov[.]br, poa[.]sp[.]gov[.]br, protocolo[.]sorocaba[.]sp[.]gov[.]br, cravinhos[.]sp[.]gov[.]br