Brazilian Banking Trojan Actively Spreading in Portugal

Brazilian Banking Trojan Continues to Spread in Portugal, Exploiting Language Barrier

A notorious banking Trojan, Lampion, has been causing trouble for Portuguese organizations since its discovery around 2019. Despite being nearly a decade old, this malware remains a threat, with researchers at Acronis observing ongoing attacks against businesses in Portugal. The fact that the attackers have chosen to target Portuguese companies may seem surprising, given the language barrier between Brazil and Europe. However, it’s precisely this cultural similarity that has made these organizations easy prey.

Lampion attacks typically begin with phishing emails, often impersonating financial or administrative bodies. In most cases, the attackers have mimicked Portugal’s Tax and Customs Authority, suggesting to victims that they had unpaid debts. More recently, however, the attackers have opted for a more nuanced approach, impersonating private sector organizations in Portugal, warning victims about pending financial issues.

One phishing email template, observed by Acronis researchers, even went so far as to include electronic receipts for fictional transactions, complete with real branding and iconography. The emails are designed to look legitimate, making it difficult for victims to distinguish between fact and fiction. Those who fall for the lure end up downloading a zip file, which extracts to trigger a web page mimicking Portugal’s most recognizable internet portal, SAPO.

In the background, however, more sinister activity is taking place. The malware establishes persistence via scheduled tasks, connects to a remote command-and-control server, and performs various housekeeping tasks. At the end of the infection chain lies a dynamic link library (DLL), which functions as the primary remote access Trojan (RAT). Lampion can inject overlays into Portuguese banking websites to steal victims’ credentials and gather reconnaissance data.

According to Jozsef Gegeny, senior researcher at Acronis, “attackers keep using techniques that haven’t changed much…there is a reason for that: If these techniques continue to generate returns, then there is going to be very little incentive for them to redesign it fundamentally.” In other words, the attackers have found a winning formula and see no need to change it.

What makes Lampion particularly effective is its ability to adapt to changing environments. As Gegeny notes, “The longevity of Lampion shows that some ATT&CK models are remarkably resilient…they don’t always need a groundbreaking innovation to be successful.” This means that the attackers can incrementally update their tactics to stay ahead of defenses.

It’s worth noting that Lampion attacks have been largely confined to Portugal, with only a few instances targeting Spain and England. This suggests that the attackers have been using geofencing techniques to prevent their tailored attacks from leaking into irrelevant regions. For Portuguese organizations, this raises concerns about their unique vulnerability in the global cyber threat landscape.

In light of these findings, it’s essential for Portuguese businesses to take proactive measures to protect themselves against Lampion and similar threats. This includes implementing robust email filtering and security protocols, as well as educating employees on the dangers of phishing attacks. By staying vigilant and adapting to evolving threats, organizations can minimize their risk exposure and stay ahead of the attackers.


Source: Dark Reading — 2026-07-23