An old Brazilian banking malware is still making rounds today, in ongoing attacks against Portuguese organizations.
"Lampion" — named after Japanese-style paper lamps — is a banking Trojan believed to have originated in Brazil, where banking Trojans are as culturally native as samba music. It was first discovered around the 2019 holiday season, and Portuguese organizations haven't given hackers all that much reason to modify it. Researchers at Acronis found that it's still being used in attacks today, largely in the same form it came in years ago.
New Lampion Banking Campaign
Lampion attacks have almost always begun with phishing emails impersonating some sort of financial or administrative body. For most of its history — as early as 2019, and as recently as 2025 — its proprietors have mimicked Portugal's Tax and Customs Authority, suggesting that potential victims had some sort of issue relating to overdue government debts.
In the ongoing campaign observed by Acronis, the attackers opted to impersonate private sector organizations in Portugal, warning victims about a pending financial or administrative issue. In one phishing email template, for instance, the attackers have been impersonating an automotive documentation agency, sending victims emails with fake electronic receipts for imagined transactions they made. The emails are decked out with all of the real iconography and information associated with the impersonated brand, and even a confidentiality notice and email signature featuring a social link.
Victims who fall for the lure end up downloading a zip file. Upon extraction, the zip triggers a Web page mimicking Portugal's most recognizable Internet portal, SAPO. In the background, meanwhile, the stage is being set for follow-on VBS scripts, which establish persistence via scheduled tasks, connect to a remote command-and-control (C2) server, and perform a variety of other housekeeping tasks. One inescapable characteristic of Lampion attacks is the hamfisted use of obfuscation techniques, anywhere and everywhere, designed to help the malware evade basic malware detection.
At the end of the infection chain lies a dynamic link library (DLL), which functions as the primary remote access Trojan (RAT). According to reports over the years, Lampion can inject overlays into Portuguese banking websites to steal victims' credentials, and glean a variety of other useful, standard reconnaissance data, like details about the victim's machine and browser.
Jozsef Gegeny, a senior researcher at Acronis, acknowledges that in the seven years since Lampion was created, "attackers keep using techniques that haven't changed much, and there is a reason for that: If these techniques continue to generate returns, then there is going to be very little incentive for them to redesign it fundamentally."
In his view, "The longevity of Lampion shows that some ATT&CK models are remarkably resilient, and they don't always need a groundbreaking innovation to be successful. Maybe just enough for them to incrementally adapt to changes in target environments."
Brazil's Threat to Portugal
Lampion attacks have always been ultra-specific to Portugal, and that continues to be the case today. Some 96.4% of recent attacks have hit this one country, with a few stragglers reaching Spain and England, suggesting that the attackers have been using geofencing to prevent their tailored attacks leaking to irrelevant regions.
And it speaks to Portugal's unique disadvantage in the global cyber threat landscape. Brazil has one of the world's most active cybercrime scenes, and Portugal is the second largest of a handful of countries where nearly everyone speaks the same native tongue as the Brazilian hackers, so Portugal is where many of the attacks naturally flow.
Santiago Pontrioli, threat intelligence research lead at Acronis, recalls learning about the motivations of Brazilian threat actors one year at a "You sh0t the Sheriff" conference in São Paulo. "There was one comment that really stuck with me," he says. "They said they have a really big criminal ecosystem in Brazil, but they usually target victims outside Brazil because of law enforcement."
"They first target countries with the same language — so that's Portugal, Angola, Zimbabwe — and then Spanish-speaking countries. But they try to do it outside Brazil so it's more difficult for the police to actually do something about it. Because if you target Portugal, you need to involve Interpol. And they know it gets more difficult for the police to actually take them down," he explains, thanks to the extra administrative glut when more agencies are investigating across more countries.
The results bear out in the data. In a survey titled "The View of Portuguese Companies on Risks," risk management firm Marsh Risk found that cyberattacks have become the number one risk to Portuguese organizations in 2026. It was the first time in the 12-year history of this report that cyber eclipsed more conventional risks like political and social instability.
Brazilian threat actors "already have the infrastructure in place, they have the business model, and Portugal is the easiest target for them," Pontrioli says. "That's the key."
Read more about:
Europe












No comments:
Post a Comment