avoid censorship @ blogspot
say the world is such a wonderful place
no problems whatsoever
|\| ART BLOG HUMOR BLOG PHOTO BLOG CULTURE BLOG |:| FOR THE RENAISSANCE MAN & THE POLYMATH WOMAN |/|
1 de 335
| 16:36 (há 4 minutos) | |||
| ||||
Olá,
Como deve saber, as nossas regras da comunidade (https://blogger.com/go/
Porque é que a sua mensagem no blogue foi eliminada?
O seu conteúdo foi avaliado com base na nossa Política de Incitamento ao Ódio. Para saber mais, visite a página das regras da comunidade cujo link se encontra neste email.
Se considerar que cometemos um erro, pode pedir um recurso em https://www.blogger.com/go/
Para mais informações, consulte os seguintes recursos:
Termos de Utilização: https://www.google.com/intl/
Política de Conteúdo: https://www.blogger.com/go/
Recomendamos que reveja o conteúdo completo das suas publicações no blogue para se certificar de que estão em conformidade com os nossos padrões, uma vez que violações adicionais podem resultar no encerramento do seu blogue.
Atentamente,
A equipa do Blogger

Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.

An old Brazilian banking malware is still making rounds today, in ongoing attacks against Portuguese organizations.
"Lampion" — named after Japanese-style paper lamps — is a banking Trojan believed to have originated in Brazil, where banking Trojans are as culturally native as samba music. It was first discovered around the 2019 holiday season, and Portuguese organizations haven't given hackers all that much reason to modify it. Researchers at Acronis found that it's still being used in attacks today, largely in the same form it came in years ago.
Lampion attacks have almost always begun with phishing emails impersonating some sort of financial or administrative body. For most of its history — as early as 2019, and as recently as 2025 — its proprietors have mimicked Portugal's Tax and Customs Authority, suggesting that potential victims had some sort of issue relating to overdue government debts.
Related:Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
In the ongoing campaign observed by Acronis, the attackers opted to impersonate private sector organizations in Portugal, warning victims about a pending financial or administrative issue. In one phishing email template, for instance, the attackers have been impersonating an automotive documentation agency, sending victims emails with fake electronic receipts for imagined transactions they made. The emails are decked out with all of the real iconography and information associated with the impersonated brand, and even a confidentiality notice and email signature featuring a social link.
Victims who fall for the lure end up downloading a zip file. Upon extraction, the zip triggers a Web page mimicking Portugal's most recognizable Internet portal, SAPO. In the background, meanwhile, the stage is being set for follow-on VBS scripts, which establish persistence via scheduled tasks, connect to a remote command-and-control (C2) server, and perform a variety of other housekeeping tasks. One inescapable characteristic of Lampion attacks is the hamfisted use of obfuscation techniques, anywhere and everywhere, designed to help the malware evade basic malware detection.
At the end of the infection chain lies a dynamic link library (DLL), which functions as the primary remote access Trojan (RAT). According to reports over the years, Lampion can inject overlays into Portuguese banking websites to steal victims' credentials, and glean a variety of other useful, standard reconnaissance data, like details about the victim's machine and browser.
Jozsef Gegeny, a senior researcher at Acronis, acknowledges that in the seven years since Lampion was created, "attackers keep using techniques that haven't changed much, and there is a reason for that: If these techniques continue to generate returns, then there is going to be very little incentive for them to redesign it fundamentally."
Related:Ransomware Thugs Masquerade as Interpol to Entice Small Biz
In his view, "The longevity of Lampion shows that some ATT&CK models are remarkably resilient, and they don't always need a groundbreaking innovation to be successful. Maybe just enough for them to incrementally adapt to changes in target environments."
Lampion attacks have always been ultra-specific to Portugal, and that continues to be the case today. Some 96.4% of recent attacks have hit this one country, with a few stragglers reaching Spain and England, suggesting that the attackers have been using geofencing to prevent their tailored attacks leaking to irrelevant regions.
And it speaks to Portugal's unique disadvantage in the global cyber threat landscape. Brazil has one of the world's most active cybercrime scenes, and Portugal is the second largest of a handful of countries where nearly everyone speaks the same native tongue as the Brazilian hackers, so Portugal is where many of the attacks naturally flow.
Related:Phishers Gain Persistence at EU, Asia Hospitality Orgs
Santiago Pontrioli, threat intelligence research lead at Acronis, recalls learning about the motivations of Brazilian threat actors one year at a "You sh0t the Sheriff" conference in São Paulo. "There was one comment that really stuck with me," he says. "They said they have a really big criminal ecosystem in Brazil, but they usually target victims outside Brazil because of law enforcement."
"They first target countries with the same language — so that's Portugal, Angola, Zimbabwe — and then Spanish-speaking countries. But they try to do it outside Brazil so it's more difficult for the police to actually do something about it. Because if you target Portugal, you need to involve Interpol. And they know it gets more difficult for the police to actually take them down," he explains, thanks to the extra administrative glut when more agencies are investigating across more countries.
The results bear out in the data. In a survey titled "The View of Portuguese Companies on Risks," risk management firm Marsh Risk found that cyberattacks have become the number one risk to Portuguese organizations in 2026. It was the first time in the 12-year history of this report that cyber eclipsed more conventional risks like political and social instability.
Brazilian threat actors "already have the infrastructure in place, they have the business model, and Portugal is the easiest target for them," Pontrioli says. "That's the key."
Read more about:
EuropeContributing Writer
Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.
He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.
He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.
Prevention at Machine Speed: Hunting Beyond Known Detections
0-Day to 10x Discovery: Security at the Speed of Mythos
When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure
Governing the Agent; Identity Security in the Age of Autonomous AI
Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything



Aug 1-6 | Mandalay Bay, Las Vegas Use code: DARKREADING & save $200 on a Briefings pass or $100 on a Business pass