Brazilian Banking Trojan 'Lampion' Actively Targets Portuguese Organizations
An old but persistent Brazilian banking Trojan, dubbed 'Lampion,' continues to target businesses in Portugal, exploiting social engineering tactics and the shared language for financial fraud.

A banking Trojan with roots in Brazil, known as 'Lampion,' is actively engaged in ongoing cyberattacks against organizations in Portugal. First identified around the 2019 holiday season, the malware has seen minimal fundamental changes, yet continues to prove effective due to its reliance on well-established social engineering techniques.
Researchers at Acronis have observed a recent campaign where Lampion attackers are impersonating private sector entities in Portugal, sending phishing emails that warn recipients of fabricated financial or administrative issues. One common tactic involves mimicking an automotive documentation agency, sending fake electronic receipts for non-existent transactions. These emails are meticulously crafted with authentic branding, iconography, and even confidentiality notices to appear legitimate, aiming to trick recipients into downloading malicious attachments.
Upon opening a malicious zip file, victims are led to a webpage that mimics SAPO, Portugal's prominent internet portal. Simultaneously, the attack chain initiates background processes involving VBS scripts. These scripts establish persistence on the compromised system by creating scheduled tasks, connect to a remote command-and-control (C2) server, and perform other essential reconnaissance and preparatory actions. A hallmark of Lampion attacks is the pervasive use of obfuscation techniques, designed to evade standard malware detection mechanisms.
The ultimate payload of the Lampion infection chain is a dynamic link library (DLL) that functions as a primary remote access Trojan (RAT). Historical reports indicate that Lampion is capable of injecting fake login pages, or overlays, into legitimate Portuguese banking websites to steal user credentials. It also gathers other sensitive information, including details about the victim's machine and browser, aiding further exploitation.
Despite the evolution of the cyber threat landscape, the longevity of Lampion highlights the resilience of certain attack models. According to Jozsef Gegeny, a senior researcher at Acronis, attackers have little incentive to fundamentally redesign such tools if they continue to yield profitable results. This suggests that incremental adaptations to target environments are often sufficient for sustained success.
Lampion's attacks exhibit a strong geographical focus, with approximately 96.4% of recent campaigns targeting Portugal. While a small number of attacks have been detected in Spain and England, the attackers appear to be employing geofencing to prevent their tailored campaigns from spreading to irrelevant regions. This specificity is linked to Portugal's unique vulnerability as a primary target for Brazilian cybercriminals.
Brazil possesses one of the most active cybercrime ecosystems globally. For Brazilian threat actors, Portugal represents an ideal target due to the shared Portuguese language, which facilitates sophisticated social engineering. Threat intelligence research lead at Acronis, Santiago Pontrioli, notes that Brazilian cybercriminals often target victims outside Brazil, including Portuguese-speaking nations, to complicate law enforcement investigations by necessitating international cooperation through bodies like Interpol.
The effectiveness of these tactics is reflected in risk management data. A survey by Marsh Risk found that cyberattacks have become the number one risk for Portuguese organizations in 2026, surpassing traditional concerns like political and social instability. This underscores the significant threat posed by Brazilian threat actors who leverage existing infrastructure and a proven business model to exploit Portugal as an accessible target.