Darkreading
Lampion Phishing Campaign Targets Portuguese Businesses with Banking Trojan
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Lampion malware campaign has intensified, focusing on Portuguese victims through targeted phishing emails. These emails impersonate financial or administrative entities, leading victims to download malicious ZIP files containing a web document that mimics SAPO, a popular Portuguese portal. Once executed, the malware retrieves additional payloads and establishes a connection to a command-and-control server. Researchers from Acronis report that 94.6% of detections are in Portugal, indicating a highly localized attack. The malware is designed to steal banking credentials and other sensitive information. Despite being first discovered in 2019, the techniques used remain largely unchanged, suggesting ongoing effectiveness. The campaign is characterized by heavy obfuscation to evade detection and strict geofencing to limit payload delivery.
Key Points: • Lampion malware primarily targets Portuguese organizations through phishing emails. • The campaign uses sophisticated social engineering tactics to increase credibility. • Despite its age, the malware remains effective with little modification over the years.