Skip to content
Lampion Malware Campaign Targets Portuguese Organizations with Phishing Attacks

Lampion Malware Campaign Targets Portuguese Organizations with Phishing Attacks

First seen 23 Jul 2026, 09:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 24, 2026 at 04:34 UTC
  • Lampion malware primarily targets Portuguese organizations through phishing emails.
  • Recent campaigns impersonate private sector entities to increase credibility.
  • The final payload is a DLL functioning as a remote access Trojan (RAT) for credential theft.

The Lampion malware campaign, originating from Brazil, is actively targeting Portuguese organizations through phishing emails. Recent attacks impersonate private sector entities, such as automotive documentation agencies, using fake receipts to lure victims. The phishing emails lead to the download of a malicious ZIP file that, when extracted, directs users to a counterfeit SAPO portal. This portal executes VBS scripts to establish persistence and connect to command-and-control servers. The final payload is a dynamic link library (DLL) that functions as a remote access Trojan (RAT), capable of stealing credentials from banking websites. The campaign has been ongoing since at least 2019, with techniques remaining largely unchanged. Researchers attribute the malware's persistence to the effective exploitation of linguistic ties between Brazilian hackers and Portuguese victims. The majority of attacks are concentrated in Portugal, making it a significant target for these threat actors.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2019-12-01
Lampion malware first discovered
Lampion was initially identified during the 2019 holiday season, targeting financial institutions.
Darkreading
2026-06-01
Recent phishing emails detected
Phishing emails impersonating financial bodies were reported, leading to malicious downloads.
Acronis
2026-07-21
Ongoing Lampion campaign reported
Acronis reported a wave of targeted phishing attacks in Portugal using Lampion malware.
Acronis
2026-07-23
Darkreading confirms ongoing attacks
Darkreading noted that the Lampion banking Trojan is still effectively targeting Portuguese organizations.
Darkreading

More articles in this cluster (6)

Following this threat?

Track Lampion in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed