(01) - CybersecurityDMSA-2025-BR-001
Phishing Campaign Impersonating pcivil.rj.gov.br
Security researchers identified a phishing campaign mimicking the Civil Registry Portal of Rio de Janeiro, Brazil, designed to steal user credentials and personal data.
Executive Summary
Dymo's automated threat detection systems identified a phishing campaign specifically targeting users of the Civil Registry Portal (pcivil.rj.gov.br) operated by the Government of Rio de Janeiro, Brazil. Attackers created convincing fake portals to harvest sensitive user data.
Campaign Details
Target Information
- Official Portal: pcivil.rj.gov.br
- Organization: Government of Rio de Janeiro
- Function: Civil registry services, vital records
- Users Affected: Brazilian citizens seeking civil documentation
Attack Methodology
The threat actors employed multiple techniques:
- Domain Registration: Acquired lookalike domains (e.g., pcivil-rj.com, pcivil-gov-br.com)
- Site Cloning: Complete replication of the official interface
- Credential Harvesting: Fake login forms capturing username/password
- Data Exfiltration: Real-time transmission of captured data
Information at Risk
Victims who interacted with the fake portals may have exposed:
- CPF (Brazilian tax ID) numbers
- Full names and addresses
- Birth dates and family information
- Login credentials
- Security questions and answers
Technical Analysis
Infrastructure
- Newly registered domains (within weeks of detection)
- Free hosting providers used
- Rapid domain rotation to evade blacklists
- Multiple redirect chains to obscure final destination
Red Flags Identified
- Mismatched SSL certificates
- URL differences from official domain
- Form submissions to third-party endpoints
- Absence of proper security headers
Remediation
For affected users:
- Change passwords immediately if credentials were submitted
- Monitor financial statements for unauthorized activity
- Consider credit freezes with Brazilian credit bureaus
- Report identity theft to proper authorities
For authorities:
- Domain suspension requests to registrars
- IP blocking at major ISPs
- Public awareness campaigns
This campaign was detected through Dymo's continuous scanning and threat intelligence platform.