Darkreading Lampion Malware Campaign Targets Portuguese Organizations with Phishing Attacks
Article Content
- •Lampion malware primarily targets Portuguese organizations through phishing emails.
- •Recent campaigns impersonate private sector entities to increase credibility.
- •The final payload is a DLL functioning as a remote access Trojan (RAT) for credential theft.
The Lampion malware campaign, originating from Brazil, is actively targeting Portuguese organizations through phishing emails. Recent attacks impersonate private sector entities, such as automotive documentation agencies, using fake receipts to lure victims. The phishing emails lead to the download of a malicious ZIP file that, when extracted, directs users to a counterfeit SAPO portal. This portal executes VBS scripts to establish persistence and connect to command-and-control servers. The final payload is a dynamic link library (DLL) that functions as a remote access Trojan (RAT), capable of stealing credentials from banking websites. The campaign has been ongoing since at least 2019, with techniques remaining largely unchanged. Researchers attribute the malware's persistence to the effective exploitation of linguistic ties between Brazilian hackers and Portuguese victims. The majority of attacks are concentrated in Portugal, making it a significant target for these threat actors.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Lampion in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…