A newly observed Lampion malware campaign is targeting Portuguese users with phishing emails disguised as routine financial and administrative messages.
Researchers at Acronis Threat Research Unit (TRU) found that the operation relies on oversized, obfuscated HTML and Visual Basic Script (VBS) files before using Windows’ rundll32.exe utility to launch a roughly 750MB remote-access Trojan (RAT).
Lampion is a Brazilian banking-malware family linked to the ChePro lineage and first documented in 2019.
Although Brazilian in origin, the malware has persistently focused on Portugal and Portuguese-speaking targets, frequently abusing themes related to finance, tax, invoices, and business administration.
The latest campaign is strongly concentrated in Portugal, which accounted for 94.6% of detections observed by Acronis.
Spain represented 4.3% and the United Kingdom 1.1%, suggesting that activity outside Portugal is likely incidental spillover rather than the campaign’s principal target base.
Lampion Malware Deploys Massive RAT
The infection begins with a phishing email that claims to contain a payment receipt or other financial document.
Messages include familiar trust-building elements, such as confidentiality notices, automated-mailbox disclaimers, corporate signatures, addresses, and social-media references, making the lure appear like ordinary business correspondence.

Victims receive a ZIP archive, such as COMPROVATIVO-JUNHO…zip, containing a large HTML file.
The HTML document is inflated to around 1.3MB with meaningless markup and random strings, a tactic designed to disrupt static analysis and reduce the effectiveness of simple signature-based detections.
When opened, the HTML file displays a fake SAPO Transfer page, abusing the branding of a well-known Portuguese online-services portal.
Embedded JavaScript silently decrypts a remote address, downloads the next-stage JavaScript, and injects it into the active browser document for execution.
Acronis said the hosting infrastructure appears to use geofencing or victim-tracking controls, making it difficult for researchers outside a genuine infection flow to collect the follow-on payloads.
This selective delivery can help attackers limit exposure of their infrastructure and malware components to analysts.

The downloaded VBS stage follows document-like naming conventions, such as Comprovativo_Junho_15-06-2026-WjGAxGL.vbs.
One analyzed sample measured about 7MB but contained only roughly 22KB of functional code; the remainder was junk variables, unnecessary routines, and encoded data intended to inflate the file and conceal its purpose. acronis
After deobfuscation, researchers found that the VBS creates a downloader in the %TEMP% directory and creates a scheduled task to retrieve and run the final VBS component.
Scheduled tasks provide attackers with a way to automate later stages and establish persistence without relying on a visible application window.
Indicators of Compromise
| IOC Type | Value |
|---|---|
| Phishing Email SHA-256 | 87efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87b |
| Phishing Email SHA-256 | ab46f7c4d3f717bb1e61d2f236917976d2a85be6958ae099fee79ea6e9031e37 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.