● News

Lampion Banking Trojan Strikes Portuguese Users With Massive 750MB Payload

July 24, 2026 · snewle
Lampion Banking Trojan Strikes Portuguese Users With Massive 750MB Payload

A sophisticated Lampion malware campaign is actively targeting users in Portugal through highly localized phishing attacks that deploy an unusually large 750MB remote access trojan payload. The operation represents the latest evolution of the Brazilian-origin banking trojan, demonstrating increased targeting precision against Portuguese-speaking populations outside its country of origin.

What Makes This Lampion Campaign Distinctive?

First identified and documented in 2019, Lampion has consistently targeted Portuguese-speaking victims rather than Brazilian users despite its Brazilian origins. The current campaign employs multistage attack methods that begin with convincing financial-themed phishing emails designed to appear as routine communications. These localized lures are specifically crafted to deceive Portuguese users by mimicking legitimate financial institutions and business correspondence common in Portugal.

How Does the Attack Infrastructure Work?

The attack chain relies on multiple stages to evade detection and successfully compromise target systems. Attackers initiate contact through carefully designed phishing emails that exploit trust in financial communications. Once a victim engages with the malicious content, the infection process begins, ultimately deploying the substantial 750MB RAT payload onto compromised systems. This unusually large file size suggests the malware package includes extensive functionality or additional tools beyond typical banking trojan capabilities.

Why Are Portuguese Users Being Targeted?

The consistent focus on Portuguese-speaking populations outside Brazil indicates a strategic targeting decision by the threat actors behind Lampion. Rather than attacking victims within their home country, the operators have maintained focus on Portugal throughout the trojan’s documented history since 2019. This geographic targeting pattern suggests either specific financial motivations related to Portuguese banking systems or a deliberate operational security decision to avoid domestic law enforcement attention.

What Does This Mean for Portuguese Organizations?

The continued evolution of the Lampion banking trojan demonstrates that threat actors are refining their tactics and improving their targeting capabilities. The use of localized phishing content shows significant investment in social engineering research to understand Portuguese business communications and financial procedures. Organizations and individual users in Portugal should maintain heightened awareness of financial-themed emails and implement robust email security measures to defend against these targeted phishing attempts.

Source: GBHackers Security