Threats Affecting Portugal
View all threats affecting or targeting Portugal. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Portugal
Click on any threat for detailed analysis and mitigation recommendations
Trezor warned customers that threat actors who breached its third-party email provider are conducting phishing attacks targeting its users. The phishing emails impersonate Trezor and claim a critical hardware vulnerability, attempting to trick recipients into clicking malicious links. Trezor has taken down the fraudulent domain and is investigating the breach. This incident follows a prior data breach involving Trezor's shipping provider ShipMonk, which exposed customer order data affecting tens of thousands of users across multiple countries. The phishing attack leverages compromised email infrastructure rather than a direct vulnerability in Trezor products. Join the discussion | Bleeping Computer | 09/10/2026, 06:56:33 UTC Added: 09/10/2026, 07:07:20 UTC |
BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, functioning as a comprehensive toolkit for Initial Access Brokers. Unlike standard infostealers, BraZetsu transforms compromised systems into commercial assets through deep reconnaissance capabilities targeting Iberian and Latin American corporate, financial, industrial, and law enforcement environments. The framework scans for standardized financial remittance files in Brazilian CNAB format, extracts detailed browser histories, and employs AI-enhanced data triage for target prioritization. Operating through a modular architecture with stealth techniques, BraZetsu powers the Infected Marketplace where Exilware commercializes initial access to compromised hosts. The platform allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect. Tracked since February 2026, BraZetsu demonstrates rapid technical progressi... Join the discussion | AlienVault OTX General | 08/31/2026, 15:42:36 UTC Added: 09/01/2026, 08:52:34 UTC |
AnonyMousKIT is an AI-powered Phishing-as-a-Service platform that targets stolen Apple devices by disabling Activation Lock. It automates credential harvesting via email, SMS, WhatsApp, and AI-driven voice phishing calls, primarily targeting device owners with personalized lures. The platform operates through a decentralized supply chain with hundreds of reseller storefronts and operators, mainly conducting vishing calls to Brazil. Operational logs leaked due to coding vulnerabilities reveal extensive infrastructure and operator details. This campaign monetizes stolen iPhones by bypassing security features through industrialized social engineering. MediumCampaign Join the discussion | AlienVault OTX General | 08/27/2026, 08:04:55 UTC Added: 08/28/2026, 00:37:15 UTC |
Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers. The post 14,000 Trezor Customers Impacted by Data Breach at ShipMonk appeared first on SecurityWeek . Join the discussion | SecurityWeek | 08/14/2026, 08:16:00 UTC Added: 08/14/2026, 08:26:13 UTC |
A data breach occurred at ShipMonk, a shipping provider for Trezor, exposing personal details of approximately 13,689 customers who placed orders between May and August 2026. Exposed data includes full names, email addresses, phone numbers, and shipping addresses. Trezor's own systems and hardware wallets were not compromised. The breach increases the risk of phishing attacks targeting affected customers. Trezor has notified impacted individuals and is working with ShipMonk to investigate and secure systems. Customers are advised to be vigilant against phishing and not to share wallet backups or sensitive information. Join the discussion | Reddit Cybersecurity | 08/13/2026, 19:04:55 UTC Added: 08/13/2026, 20:11:06 UTC |
Trezor, a hardware wallet manufacturer, disclosed a data breach affecting nearly 14,000 customers due to a hack of its shipping provider, ShipMonk. The attackers accessed customer order data including full names, shipping addresses, email addresses, and phone numbers. The breach impacts customers from multiple countries who received orders between May 10 and August 8, 2026. Trezor's own systems and devices were not compromised, but affected customers may face increased phishing attempts using the stolen data. The company warns users to be vigilant against scams impersonating banks, crypto exchanges, or Trezor itself. Join the discussion | Bleeping Computer | 08/13/2026, 15:13:19 UTC Added: 08/13/2026, 15:26:18 UTC |
An active Lampion malware campaign has been identified targeting Portuguese users through phishing emails that impersonate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, delivers initial payloads via ZIP archives containing heavily obfuscated HTML files designed to evade detection. The HTML stage retrieves additional scripts from attacker-controlled infrastructure, initiating a multistage VBS infection chain. Each stage employs extensive obfuscation techniques including junk code, encrypted strings, and dynamically generated scripts that inflate file sizes while concealing core functionality. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis. Telemetry shows 94.6% of detections concentrated in Portugal, confirming this is a highly targeted threat focused on Portuguese-speaking victims. Join the discussion | AlienVault OTX General | 07/21/2026, 16:05:04 UTC Added: 07/22/2026, 08:07:06 UTC |
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025. Join the discussion | AlienVault OTX General | 07/14/2026, 16:36:39 UTC Added: 07/16/2026, 10:17:37 UTC |
Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via AntSword, before deploying Nezha, an open-source monitoring tool, to facilitate remote command execution. This led to the deployment of Ghost RAT on compromised systems. Analysis revealed over 100 compromised machines, predominantly located in Taiwan, Japan, South Korea, and Hong Kong. The attackers demonstrated technical proficiency through multi-stage operations, utilizing AWS and VPS infrastructure, with indicators pointing to China-nexus threat actors. The campaign highlights increasing abuse of legitimate publicly available tools to achieve malicious objectives while maintaining plausible deniability. Join the discussion | AlienVault OTX General | 07/03/2026, 21:26:02 UTC Added: 07/06/2026, 09:21:27 UTC |
In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets. Join the discussion | AlienVault OTX General | 07/01/2026, 21:35:11 UTC Added: 07/02/2026, 07:06:43 UTC |
Showing 1 to 10 of 318 results