- What: Lampion banking malware continues to target Portuguese organizations
- Impact: Portuguese businesses and individuals are at risk from phishing attacks and malware
Endpoint/Device Security , Threat Intelligence Lampion banking malware continues to target Portuguese organizations July 23, 2026 Share By SC Staff (Adobe Stock) A banking Trojan known as Lampion, believed to have originated in Brazil, is still actively used in ongoing attacks targeting Portuguese organizations. First discovered around the 2019 holiday season, the malware has remained largely unchanged and continues to be effective, as first reported by Dark Reading. Lampion attacks typically commence with phishing emails impersonating financial or administrative entities. While historically mimicking Portugal's Tax and Customs Authority, recent campaigns have seen attackers posing as private sector organizations, such as an automotive documentation agency, to lure victims with fake receipts. Upon opening a malicious zip file, victims are directed to a fake SAPO portal, leading to VBS scripts that establish persistence, connect to command-and-control servers, and employ obfuscation techniques to evade detection. The final payload is a dynamic link library (DLL) functioning as a remote access Trojan (RAT), capable of injecting overlays into banking websites to steal credentials and gather reconnaissance data. Researchers note that the malware's longevity is due to the continued effectiveness of its unchanged techniques. The vast majority of Lampion attacks are concentrated in Portugal, a consequence of Brazil's robust cybercrime ecosystem and the linguistic ties between the two nations, making Portugal an accessible target for Brazilian threat actors seeking to operate outside their home country's law enforcement reach. Cyberattacks have now surpassed conventional risks as the primary concern for Portuguese organizations. Source: Dark Reading SC Staff Related Endpoint/Device Security Ivanti introduces predictive remediation for endpoint management SC Staff July 22, 2026 The predictive remediation feature, built on the Ivanti Neurons platform, works alongside Autonomous Patch Management. Endpoint/Device Security Windows bind links exploited for EDR evasion SC Staff July 16, 2026 The researchers detailed three methods: file-binding, process-binding, and silo-binding. Endpoint/Device Security Old Microsoft-signed UEFI applications can bypass Secure Boot SC Staff July 14, 2026 These vulnerable UEFI applications, primarily older versions of the shim bootloader, can allow attackers to execute untrusted code during system startup, according to ESET researcher Martin Smolár. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Brute Force Domain Hijacking Drive-by Download Firmware Hybrid Attack Information Warfare Keylogger Morris Worm Password Cracking Reconnaissance You can skip this ad in 5 seconds