The Lampion banking malware operators have intensified phishing campaigns against Portuguese organizations, with activity heavily concentrated in Portugal and targeting sectors including government, finance, transportation, and private industry. Researchers said the infection chain uses ZIP attachments that lead victims to fake Portuguese-themed websites, including pages impersonating the country’s tax authority and other local organizations, to deliver social-engineering prompts that push users toward malware execution.
In observed attacks, victims were tricked with a ClickFix lure into launching a malicious PowerShell command, which then fetched multiple heavily obfuscated VBScript stages designed for persistence, reconnaissance, evasion, and command-and-control communication. The malware checks for security tools and sandbox or virtualized environments, exfiltrates a Base64-encoded victim identifier to cloud-hosted infrastructure, and prepares delivery of a large DLL-based remote-access payload associated with Lampion, although one observed chain stopped short of deploying the final payload because the download command was commented out.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Dark Reading reported Acronis researchers observed Lampion actively spreading in Portugal through phishing campaigns that use ZIP attachments, fake Portuguese-themed content, VBS scripts, and a DLL-based RAT payload. The activity was described as overwhelmingly concentrated in Portugal and included impersonation of private-sector Portuguese organizations.
Unit 42 said the Lampion banking malware operators have been active since at least 2019, establishing the long-running background for the campaign.
Unit 42 reported a highly targeted campaign against dozens of Portuguese organizations, especially in government, finance, and transportation, using phishing emails, fake Portuguese tax authority pages, and ClickFix social engineering. The observed chain delivered multiple obfuscated VBScript stages and infrastructure consistent with prior Lampion operations, though the final payload was not delivered in the captured activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 104 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
8 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcecyberveille.ch
Open sourcedarkreading.com
Open sourceacronis.com
Open sourceunit42.paloaltonetworks.com
Open sourceseguranca-informatica.pt
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.