news.mlab.sh
Back to the feed
threat-intel

Brazilian Banking Trojan Actively Spreading in Portugal

High
Summary

A long-standing Brazilian banking Trojan, Lampion, is actively targeting Portuguese organizations, leveraging the shared language and cultural connection between Brazilian hackers and Portuguese businesses. The malware, first discovered in 2019, continues to be used in largely unchanged form, relying on sophisticated phishing campaigns mimicking Portuguese government agencies and other organizations. Attacks are highly targeted, with 96.4% occurring in Portugal, and a small number extending to Spain and England, due to geofencing techniques employed by the attackers to avoid detection and complicate investigations.

A persistent Brazilian banking Trojan, known as Lampion, is currently targeting Portuguese organizations. The malware has been active since 2019 and continues to be utilized in largely unchanged form, demonstrating a remarkable resilience in the face of evolving cybersecurity measures. Lampion’s success hinges on highly targeted phishing campaigns, frequently impersonating Portuguese government agencies and other organizations to trick victims into downloading malicious files. These emails often include realistic branding and even confidentiality notices, mimicking legitimate communications.

Upon extraction, a zip file triggers a Web page mimicking Portugal’s most recognizable Internet portal, SAPO. In the background, VBS scripts are executed, establishing persistence via scheduled tasks, connecting to a remote command-and-control (C2) server, and performing various housekeeping tasks. A key component of Lampion is its use of obfuscation techniques to evade basic malware detection.

The Trojan functions as a remote access Trojan (RAT), injecting overlays into Portuguese banking websites to steal credentials and gather reconnaissance data about the victim’s machine and browser. Researchers at Acronis have noted that Lampion’s longevity is due to the attackers’ continued use of established techniques, as these consistently generate returns and offer little incentive for fundamental redesign.

Attacks are overwhelmingly concentrated in Portugal, with 96.4% of recent incidents occurring within the country, and a small number extending to Spain and England, utilizing geofencing to limit the scope of attacks. This geographic targeting is driven by the shared language between Brazilian hackers and Portuguese businesses, making Portugal a prime target. A 2026 report by Marsh Risk highlighted that cyberattacks have become the top risk for Portuguese organizations, marking the first time in the report’s 12-year history that cyber eclipsed more traditional risks like political and social instability. Brazilian threat actors have a well-established infrastructure and business model, and Portugal represents a convenient target due to its linguistic similarities and relative ease of investigation for the attackers, as it necessitates involvement of Interpol, adding to the complexity for Portuguese law enforcement.

Read the full article at Dark Reading