Lampion malware operators are a financially motivated cybercrime threat actor associated with campaigns targeting organizations in Portugal. The actor has been observed targeting government, financial, and transport entities and using social-engineering lures to induce victims to execute malicious PowerShell commands. In documented activity, the operators adopted a ClickFix-style technique, presenting fraudulent troubleshooting prompts to trick users into manually launching attacker-supplied commands. This tradecraft indicates emphasis on initial access through user deception and hands-on execution rather than purely automated exploitation. The actor is associated with the Lampion banking malware ecosystem and has targeted sectors likely to provide access to sensitive financial information and organizational systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.