Researchers reported renewed activity from the Lampion banking trojan, a malware family that has targeted Portuguese internet users since 2019 through phishing messages impersonating tax and banking institutions. The latest observed variant, release 212, preserves Lampion’s established credential-theft workflow while introducing a more heavily obfuscated VBS loader padded with junk code and unusually large files to reduce antivirus detection. The infection chain uses an initial script to generate additional VBS files, establish persistence through a scheduled task and startup-folder artifacts, and retrieve two DLL stages from AWS S3 buckets.
The first DLL functions as a loader that extracts a password-protected second DLL containing the core Lampion payload, which retains export structures and decryption logic seen in earlier versions. Once active, the malware monitors running processes and browser page titles for hardcoded Portuguese and Brazilian banking targets, then displays overlay windows to steal credentials. Investigators also found that the campaign continued using the same command-and-control server, 5.188.9.28, reportedly geolocated in Russia, linking the operation to infrastructure observed in campaigns dating back to 2020.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
A Lampion phishing campaign used a WeTransfer link masquerading as a proof-of-payment document to deliver a ZIP archive containing a malicious VBS loader. The infection chain downloaded final DLL payloads from external URLs including Amazon S3, representing a newly observed delivery variation for Lampion.
Lampion release 212 was active in February 2022, continuing the malware family's established banking-theft activity while using a modified VBS loader padded with junk data to evade detection.
The report states Lampion had been using the same command-and-control server, 5.188.9.28, since at least 2020. Researchers also noted the server was geolocated in Russia.
Lampion was reported to have impacted Portuguese internet end users since 2019, using phishing lures impersonating Portuguese tax and banking institutions to deliver its malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cofense.com
Open sourcesecurityaffairs.co
Open sourceseguranca-informatica.pt
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.