Lampion Malware Campaign Targets Portuguese Organizations with Phishing Attacks

Lampion Malware Campaign Targets Portuguese Organizations with Phishing Attacks

First seen 23 Jul 2026, 09:23 UTC AcronisDarkreadingFeeds.Feedburnerseguranca-informatica.ptunit42.paloaltonetworks.com 83% similarity 66.5

Article Content

Browse articles
ThreatCluster

The Lampion malware campaign, originating from Brazil, is actively targeting Portuguese organizations through phishing emails. Recent attacks impersonate private sector entities, such as automotive documentation agencies, using fake receipts to lure victims. The phishing emails lead to the download of a malicious ZIP file that, when extracted, directs users to a counterfeit SAPO portal. This portal executes VBS scripts to establish persistence and connect to command-and-control servers. The final payload is a dynamic link library (DLL) that functions as a remote access Trojan (RAT), capable of stealing credentials from banking websites. The campaign has been ongoing since at least 2019, with techniques remaining largely unchanged. Researchers attribute the malware's persistence to the effective exploitation of linguistic ties between Brazilian hackers and Portuguese victims. The majority of attacks are concentrated in Portugal, making it a significant target for these threat actors.

Key Points: • Lampion malware primarily targets Portuguese organizations through phishing emails. • Recent campaigns impersonate private sector entities to increase credibility. • The final payload is a DLL functioning as a remote access Trojan (RAT) for credential theft.

ThreatCluster AI

Timeline

2019-12-01
Lampion malware first discovered
Lampion was initially identified during the 2019 holiday season, targeting financial institutions.
Darkreading
2026-06-01
Recent phishing emails detected
Phishing emails impersonating financial bodies were reported, leading to malicious downloads.
Acronis
2026-07-21
Ongoing Lampion campaign reported
Acronis reported a wave of targeted phishing attacks in Portugal using Lampion malware.
Acronis
2026-07-23
Darkreading confirms ongoing attacks
Darkreading noted that the Lampion banking Trojan is still effectively targeting Portuguese organizations.
Darkreading

Community

Browse all →