Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Portugal-focused phishing campaign delivers multistage malware

0
Medium
Published: 07/21/2026 (07/21/2026, 16:05:04 UTC)
Source: AlienVault OTX General

Description

An active Lampion malware campaign has been identified targeting Portuguese users through phishing emails that impersonate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, delivers initial payloads via ZIP archives containing heavily obfuscated HTML files designed to evade detection. The HTML stage retrieves additional scripts from attacker-controlled infrastructure, initiating a multistage VBS infection chain. Each stage employs extensive obfuscation techniques including junk code, encrypted strings, and dynamically generated scripts that inflate file sizes while concealing core functionality. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis. Telemetry shows 94.6% of detections concentrated in Portugal, confirming this is a highly targeted threat focused on Portuguese-speaking victims.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 08:24:35 UTC

Technical Analysis

This threat involves an active Lampion malware campaign targeting Portuguese users through phishing emails that mimic legitimate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, uses ZIP archives with heavily obfuscated HTML files as initial payloads. These HTML files retrieve additional scripts from attacker-controlled infrastructure, triggering a multistage VBS infection chain. Each stage employs extensive obfuscation techniques such as junk code, encrypted strings, and dynamically generated scripts to conceal core functionality and inflate file sizes. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis and detection. Telemetry data indicates a strong geographic focus on Portugal, with 94.6% of detections occurring there, confirming the campaign's targeting of Portuguese-speaking victims.

Potential Impact

The campaign delivers banking malware capable of compromising financial information of targeted Portuguese users. The multistage infection chain and heavy obfuscation techniques increase the difficulty of detection and analysis, potentially allowing the malware to persist and exfiltrate sensitive data. The phishing emails impersonate trusted financial and administrative entities, increasing the likelihood of user interaction and successful infection.

Mitigation Recommendations

No official patch or fix is available as this is a malware campaign rather than a software vulnerability. Mitigation focuses on user awareness to recognize phishing emails impersonating financial and administrative entities, blocking and monitoring the identified malicious domains and URLs, and employing advanced endpoint detection solutions capable of identifying obfuscated scripts and multistage infection behaviors. Organizations should update their email filtering and anti-malware defenses to detect the indicators of compromise provided. Since this is not a cloud service, remediation depends on local defenses and user education.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.acronis.com/en/tru/posts/lampions-portugal-focused-phishing-campaign-delivers-multistage-malware/"]
Adversary
null
Pulse Id
6a5f98b0ca49303f8f2e4aa7
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash036c8f32012abdcb9a389ae9c284da89505e830bca74eb1aa9ea3794b067aab6
hash050e84d134a32ed7c4885a9d57ce37f8ae5f910960b67e2156941961bd5781ba
hash1541c23f34eb05dfcbede3830741427681d719cee1dfd397a2c04110e0fa81b2
hash1bd347ce5deee3d783a038e2d2d224bc30cc074e0471a3897c5409ce99816dc9
hash643c0093baec45952a46b0210f7a6f8fb26883b396b66f1cb609c5b55e6dae1e
hash7ad89fb0a4a5449a381b8f540238193019673adc7cfb1c008dcd14a745891551
hash87efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87b
hashab46f7c4d3f717bb1e61d2f236917976d2a85be6958ae099fee79ea6e9031e37
hashb1c101bd1ba134ffbea61f9fac2b7c8fbd13ca113a37944abdc131ef86da92ac
hashc6618bb692fb3f5d7959f8db1fedaaac5e8a36fb901397a008aa2b88874448fd
hashd25d32478ae67403484a309591b6409224d26ca3d094c5ccd8428ebef7efcfd1
hashfe769fd85a7440751e1508614c8d9ef0de00bece803329bf3318ff863a146216

Url

ValueDescriptionCopy
urlhttps://fat-contabislitaca.com/js/1898.php

Domain

ValueDescriptionCopy
domainauto-contabilistica.com
domainautoridade-contabilistica.org
domainautoridade-financeira.com
domainfat-contabislitaca.com

Threat ID: 6a607a2a9c2644c7f8a698c2

Added to database: 07/22/2026, 08:07:06 UTC

Last enriched: 07/22/2026, 08:24:35 UTC

Last updated: 07/22/2026, 23:39:57 UTC

Views: 44

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses