A banking Trojan known as Lampion, believed to have originated in Brazil, is still actively used in ongoing attacks targeting Portuguese organizations. First discovered around the 2019 holiday season, the malware has remained largely unchanged and continues to be effective, as first reported by Dark Reading.Lampion attacks typically commence with phishing emails impersonating financial or administrative entities. While historically mimicking Portugal's Tax and Customs Authority, recent campaigns have seen attackers posing as private sector organizations, such as an automotive documentation agency, to lure victims with fake receipts. Upon opening a malicious zip file, victims are directed to a fake SAPO portal, leading to VBS scripts that establish persistence, connect to command-and-control servers, and employ obfuscation techniques to evade detection. The final payload is a dynamic link library (DLL) functioning as a remote access Trojan (RAT), capable of injecting overlays into banking websites to steal credentials and gather reconnaissance data. Researchers note that the malware's longevity is due to the continued effectiveness of its unchanged techniques. The vast majority of Lampion attacks are concentrated in Portugal, a consequence of Brazil's robust cybercrime ecosystem and the linguistic ties between the two nations, making Portugal an accessible target for Brazilian threat actors seeking to operate outside their home country's law enforcement reach. Cyberattacks have now surpassed conventional risks as the primary concern for Portuguese organizations.Source: Dark Reading
Endpoint/Device Security, Threat Intelligence
Lampion banking malware continues to target Portuguese organizations

(Adobe Stock)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



