Darkreading
Lampion Malware Campaign Targets Portuguese Organizations with Phishing Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Lampion malware campaign, originating from Brazil, is actively targeting Portuguese organizations through phishing emails. Recent attacks impersonate private sector entities, such as automotive documentation agencies, using fake receipts to lure victims. The phishing emails lead to the download of a malicious ZIP file that, when extracted, directs users to a counterfeit SAPO portal. This portal executes VBS scripts to establish persistence and connect to command-and-control servers. The final payload is a dynamic link library (DLL) that functions as a remote access Trojan (RAT), capable of stealing credentials from banking websites. The campaign has been ongoing since at least 2019, with techniques remaining largely unchanged. Researchers attribute the malware's persistence to the effective exploitation of linguistic ties between Brazilian hackers and Portuguese victims. The majority of attacks are concentrated in Portugal, making it a significant target for these threat actors.
Key Points: • Lampion malware primarily targets Portuguese organizations through phishing emails. • Recent campaigns impersonate private sector entities to increase credibility. • The final payload is a DLL functioning as a remote access Trojan (RAT) for credential theft.