Portugal-focused phishing campaign delivers multistage malware
An active Lampion malware campaign has been identified targeting Portuguese users through phishing emails that impersonate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, delivers initial payloads via ZIP archives containing heavily obfuscated HTML files designed to evade detection. The HTML stage retrieves additional scripts from attacker-controlled infrastructure, initiating a multistage VBS infection chain. Each stage employs extensive obfuscation techniques including junk code, encrypted strings, and dynamically generated scripts that inflate file sizes while concealing core functionality. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis. Telemetry shows 94.6% of detections concentrated in Portugal, confirming this is a highly targeted threat focused on Portuguese-speaking victims.
AI Analysis
Technical Summary
This threat involves an active Lampion malware campaign targeting Portuguese users through phishing emails that mimic legitimate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, uses ZIP archives with heavily obfuscated HTML files as initial payloads. These HTML files retrieve additional scripts from attacker-controlled infrastructure, triggering a multistage VBS infection chain. Each stage employs extensive obfuscation techniques such as junk code, encrypted strings, and dynamically generated scripts to conceal core functionality and inflate file sizes. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis and detection. Telemetry data indicates a strong geographic focus on Portugal, with 94.6% of detections occurring there, confirming the campaign's targeting of Portuguese-speaking victims.
Potential Impact
The campaign delivers banking malware capable of compromising financial information of targeted Portuguese users. The multistage infection chain and heavy obfuscation techniques increase the difficulty of detection and analysis, potentially allowing the malware to persist and exfiltrate sensitive data. The phishing emails impersonate trusted financial and administrative entities, increasing the likelihood of user interaction and successful infection.
Mitigation Recommendations
No official patch or fix is available as this is a malware campaign rather than a software vulnerability. Mitigation focuses on user awareness to recognize phishing emails impersonating financial and administrative entities, blocking and monitoring the identified malicious domains and URLs, and employing advanced endpoint detection solutions capable of identifying obfuscated scripts and multistage infection behaviors. Organizations should update their email filtering and anti-malware defenses to detect the indicators of compromise provided. Since this is not a cloud service, remediation depends on local defenses and user education.
Affected Countries
Portugal
Indicators of Compromise
- hash: 036c8f32012abdcb9a389ae9c284da89505e830bca74eb1aa9ea3794b067aab6
- hash: 050e84d134a32ed7c4885a9d57ce37f8ae5f910960b67e2156941961bd5781ba
- hash: 1541c23f34eb05dfcbede3830741427681d719cee1dfd397a2c04110e0fa81b2
- hash: 1bd347ce5deee3d783a038e2d2d224bc30cc074e0471a3897c5409ce99816dc9
- hash: 643c0093baec45952a46b0210f7a6f8fb26883b396b66f1cb609c5b55e6dae1e
- hash: 7ad89fb0a4a5449a381b8f540238193019673adc7cfb1c008dcd14a745891551
- hash: 87efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87b
- hash: ab46f7c4d3f717bb1e61d2f236917976d2a85be6958ae099fee79ea6e9031e37
- hash: b1c101bd1ba134ffbea61f9fac2b7c8fbd13ca113a37944abdc131ef86da92ac
- hash: c6618bb692fb3f5d7959f8db1fedaaac5e8a36fb901397a008aa2b88874448fd
- hash: d25d32478ae67403484a309591b6409224d26ca3d094c5ccd8428ebef7efcfd1
- hash: fe769fd85a7440751e1508614c8d9ef0de00bece803329bf3318ff863a146216
- url: https://fat-contabislitaca.com/js/1898.php
- domain: auto-contabilistica.com
- domain: autoridade-contabilistica.org
- domain: autoridade-financeira.com
- domain: fat-contabislitaca.com
Portugal-focused phishing campaign delivers multistage malware
Description
An active Lampion malware campaign has been identified targeting Portuguese users through phishing emails that impersonate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, delivers initial payloads via ZIP archives containing heavily obfuscated HTML files designed to evade detection. The HTML stage retrieves additional scripts from attacker-controlled infrastructure, initiating a multistage VBS infection chain. Each stage employs extensive obfuscation techniques including junk code, encrypted strings, and dynamically generated scripts that inflate file sizes while concealing core functionality. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis. Telemetry shows 94.6% of detections concentrated in Portugal, confirming this is a highly targeted threat focused on Portuguese-speaking victims.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves an active Lampion malware campaign targeting Portuguese users through phishing emails that mimic legitimate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, uses ZIP archives with heavily obfuscated HTML files as initial payloads. These HTML files retrieve additional scripts from attacker-controlled infrastructure, triggering a multistage VBS infection chain. Each stage employs extensive obfuscation techniques such as junk code, encrypted strings, and dynamically generated scripts to conceal core functionality and inflate file sizes. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis and detection. Telemetry data indicates a strong geographic focus on Portugal, with 94.6% of detections occurring there, confirming the campaign's targeting of Portuguese-speaking victims.
Potential Impact
The campaign delivers banking malware capable of compromising financial information of targeted Portuguese users. The multistage infection chain and heavy obfuscation techniques increase the difficulty of detection and analysis, potentially allowing the malware to persist and exfiltrate sensitive data. The phishing emails impersonate trusted financial and administrative entities, increasing the likelihood of user interaction and successful infection.
Mitigation Recommendations
No official patch or fix is available as this is a malware campaign rather than a software vulnerability. Mitigation focuses on user awareness to recognize phishing emails impersonating financial and administrative entities, blocking and monitoring the identified malicious domains and URLs, and employing advanced endpoint detection solutions capable of identifying obfuscated scripts and multistage infection behaviors. Organizations should update their email filtering and anti-malware defenses to detect the indicators of compromise provided. Since this is not a cloud service, remediation depends on local defenses and user education.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.acronis.com/en/tru/posts/lampions-portugal-focused-phishing-campaign-delivers-multistage-malware/"]
- Adversary
- null
- Pulse Id
- 6a5f98b0ca49303f8f2e4aa7
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash036c8f32012abdcb9a389ae9c284da89505e830bca74eb1aa9ea3794b067aab6 | — | |
hash050e84d134a32ed7c4885a9d57ce37f8ae5f910960b67e2156941961bd5781ba | — | |
hash1541c23f34eb05dfcbede3830741427681d719cee1dfd397a2c04110e0fa81b2 | — | |
hash1bd347ce5deee3d783a038e2d2d224bc30cc074e0471a3897c5409ce99816dc9 | — | |
hash643c0093baec45952a46b0210f7a6f8fb26883b396b66f1cb609c5b55e6dae1e | — | |
hash7ad89fb0a4a5449a381b8f540238193019673adc7cfb1c008dcd14a745891551 | — | |
hash87efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87b | — | |
hashab46f7c4d3f717bb1e61d2f236917976d2a85be6958ae099fee79ea6e9031e37 | — | |
hashb1c101bd1ba134ffbea61f9fac2b7c8fbd13ca113a37944abdc131ef86da92ac | — | |
hashc6618bb692fb3f5d7959f8db1fedaaac5e8a36fb901397a008aa2b88874448fd | — | |
hashd25d32478ae67403484a309591b6409224d26ca3d094c5ccd8428ebef7efcfd1 | — | |
hashfe769fd85a7440751e1508614c8d9ef0de00bece803329bf3318ff863a146216 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://fat-contabislitaca.com/js/1898.php | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainauto-contabilistica.com | — | |
domainautoridade-contabilistica.org | — | |
domainautoridade-financeira.com | — | |
domainfat-contabislitaca.com | — |
Threat ID: 6a607a2a9c2644c7f8a698c2
Added to database: 07/22/2026, 08:07:06 UTC
Last enriched: 07/22/2026, 08:24:35 UTC
Last updated: 07/22/2026, 23:39:57 UTC
Views: 44
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.