Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES THREAT INTELLIGENCE VULNERABILITIES & THREATS ENDPOINT SECURITY NEWS Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America. Brazilian Banking Trojan Actively Spreading in Portugal Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets. Nate Nelson,Contributing Writer July 23, 2026 4 Min Read Paper lanterns and garland hanging in a street.SOURCE: OLENA MALIK VIA GETTY IMAGES An old Brazilian banking malware is still making rounds today, in ongoing attacks against Portuguese organizations. "Lampion" — named after Japanese-style paper lamps — is a banking Trojan believed to have originated in Brazil, where banking Trojans are as culturally native as samba music. It was first discovered around the 2019 holiday season, and Portuguese organizations haven't given hackers all that much reason to modify it. Researchers at Acronis found that it's still being used in attacks today, largely in the same form it came in years ago. New Lampion Banking Campaign Lampion attacks have almost always begun with phishing emails impersonating some sort of financial or administrative body. For most of its history — as early as 2019, and as recently as 2025 — its proprietors have mimicked Portugal's Tax and Customs Authority, suggesting that potential victims had some sort of issue relating to overdue government debts. Related:Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain In the ongoing campaign observed by Acronis, the attackers opted to impersonate private sector organizations in Portugal, warning victims about a pending financial or administrative issue. In one phishing email template, for instance, the attackers have been impersonating an automotive documentation agency, sending victims emails with fake electronic receipts for imagined transactions they made. The emails are decked out with all of the real iconography and information associated with the impersonated brand, and even a confidentiality notice and email signature featuring a social link. Victims who fall for the lure end up downloading a zip file. Upon extraction, the zip triggers a Web page mimicking Portugal's most recognizable Internet portal, SAPO. In the background, meanwhile, the stage is being set for follow-on VBS scripts, which establish persistence via scheduled tasks, connect to a remote command-and-control (C2) server, and perform a variety of other housekeeping tasks. One inescapable characteristic of Lampion attacks is the hamfisted use of obfuscation techniques, anywhere and everywhere, designed to help the malware evade basic malware detection. At the end of the infection chain lies a dynamic link library (DLL), which functions as the primary remote access Trojan (RAT). According to reports over the years, Lampion can inject overlays into Portuguese banking websites to steal victims' credentials, and glean a variety of other useful, standard reconnaissance data, like details about the victim's machine and browser. Jozsef Gegeny, a senior researcher at Acronis, acknowledges that in the seven years since Lampion was created, "attackers keep using techniques that haven't changed much, and there is a reason for that: If these techniques continue to generate returns, then there is going to be very little incentive for them to redesign it fundamentally." Related:Ransomware Thugs Masquerade as Interpol to Entice Small Biz In his view, "The longevity of Lampion shows that some ATT&CK models are remarkably resilient, and they don't always need a groundbreaking innovation to be successful. Maybe just enough for them to incrementally adapt to changes in target environments." Brazil's Threat to Portugal Lampion attacks have always been ultra-specific to Portugal, and that continues to be the case today. Some 96.4% of recent attacks have hit this one country, with a few stragglers reaching Spain and England, suggesting that the attackers have been using geofencing to prevent their tailored attacks leaking to irrelevant regions. And it speaks to Portugal's unique disadvantage in the global cyber threat landscape. Brazil has one of the world's most active cybercrime scenes, and Portugal is the second largest of a handful of countries where nearly everyone speaks the same native tongue as the Brazilian hackers, so Portugal is where many of the attacks naturally flow. Related:Phishers Gain Persistence at EU, Asia Hospitality Orgs Santiago Pontrioli, threat intelligence research lead at Acronis, recalls learning about the motivations of Brazilian threat actors one year at a "You sh0t the Sheriff" conference in São Paulo. "There was one comment that really stuck with me," he says. "They said they have a really big criminal ecosystem in Brazil, but they usually target victims outside Brazil because of law enforcement." "They first target countries with the same language — so that's Portugal, Angola, Zimbabwe — and then Spanish-speaking countries. But they try to do it outside Brazil so it's more difficult for the police to actually do something about it. Because if you target Portugal, you need to involve Interpol. And they know it gets more difficult for the police to actually take them down," he explains, thanks to the extra administrative glut when more agencies are investigating across more countries. The results bear out in the data. In a survey titled "The View of Portuguese Companies on Risks," risk management firm Marsh Risk found that cyberattacks have become the number one risk to Portuguese organizations in 2026. It was the first time in the 12-year history of this report that cyber eclipsed more conventional risks like political and social instability. Brazilian threat actors "already have the infrastructure in place, they have the business model, and Portugal is the easiest target for them," Pontrioli says. "That's the key." Read more about: Europe About the Author Nate Nelson Contributing Writer Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media. He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify. He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days by Jai Vijayan FEB 03, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Editor's Choice VULNERABILITIES & THREATS Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes byJai Vijayan JUL 14, 2026 5 MIN READ PERIMETER 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems byAlexander Culafi JUL 14, 2026 4 MIN READ CYBERSECURITY OPERATIONS 'Yellow Teams' Are Defining the Future of AI Security byNate Nelson JUL 13, 2026 6 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices