Brazilian Banking Trojan Actively Spreading in Portugal

Brazilian Banking Trojan Still Wreaking Havoc in Portugal

A long-forgotten banking malware has resurfaced to wreak havoc on Portuguese organizations, with researchers at Acronis discovering that it’s still being used in attacks today. The “Lampion” Trojan, named after Japanese-style paper lanterns, originated in Brazil and first emerged around the 2019 holiday season.

The attackers have continued to use outdated techniques, including phishing emails impersonating financial or administrative bodies, often mimicking Portugal’s Tax and Customs Authority. These emails aim to create a sense of urgency by suggesting that potential victims have outstanding government debts. In recent campaigns, however, the attackers have shifted their targets to private sector organizations in Portugal.

Once a victim falls for the lure, they are tricked into downloading a zip file that contains the malware. Upon extraction, the zip triggers a web page mimicking Portugal’s most recognizable Internet portal, SAPO. Meanwhile, the stage is set for follow-on scripts that establish persistence via scheduled tasks and connect to a remote command-and-control (C2) server.

One of the hallmark characteristics of Lampion attacks is the use of obfuscation techniques to evade basic malware detection. However, these methods have become increasingly outdated, making it easier for security professionals to detect and prevent these types of attacks.

According to Jozsef Gegeny, a senior researcher at Acronis, the longevity of Lampion shows that some attack models are remarkably resilient and don’t always require groundbreaking innovation to be successful. “Maybe just enough for them to incrementally adapt to changes in target environments,” he notes.

The fact that 96.4% of recent attacks have targeted Portugal suggests that the attackers have been using geofencing techniques to prevent their tailored attacks leaking to irrelevant regions. This highlights Portugal’s unique disadvantage in the global cyber threat landscape, where Brazil has one of the world’s most active cybercrime scenes and Portuguese speakers are also prevalent.

The takeaway from this story is clear: outdated malware can still pose a significant threat if left unchecked. Security professionals must remain vigilant and adapt their detection methods to counter increasingly sophisticated attacks. For organizations in Portugal, it’s essential to prioritize cybersecurity measures, including robust email filtering, regular software updates, and employee education on phishing threats.

As Jozsef Gegeny notes, the success of Lampion highlights the importance of incremental adaptation by attackers. While this may not be a groundbreaking innovation, it serves as a reminder that security professionals must stay one step ahead in their efforts to prevent these types of attacks. By doing so, they can protect themselves and their organizations from the ongoing threat posed by this Brazilian banking Trojan.


Source: Dark Reading — 2026-07-23