Executive Summary
In July 2026, the Brazilian banking Trojan known as Lampion was identified in an active campaign targeting Portuguese users. The malware is disseminated through phishing emails that masquerade as financial and administrative communications, leading recipients to download malicious ZIP files. Once executed, Lampion establishes persistence, connects to a remote command-and-control server, and can inject overlays into banking websites to steal credentials. This campaign has resulted in significant data breaches and financial losses for affected individuals and organizations.
The resurgence of Lampion underscores the persistent threat posed by banking Trojans, especially those leveraging social engineering tactics. Organizations must remain vigilant, as attackers continue to exploit language and cultural similarities to enhance the effectiveness of their campaigns.
Why This Matters Now
The resurgence of Lampion highlights the evolving tactics of cybercriminals targeting Portuguese-speaking users, emphasizing the need for enhanced phishing awareness and robust cybersecurity measures to protect sensitive financial information.
Attack Path Analysis
The Lampion banking Trojan campaign begins with phishing emails impersonating financial institutions, leading victims to download malicious ZIP files. Upon extraction, obfuscated VBS scripts execute, establishing persistence and connecting to command-and-control servers. The malware then injects overlays into banking websites to steal credentials and exfiltrates sensitive data to external servers.
Kill Chain Progression
Initial Compromise
Description
Victims receive phishing emails impersonating financial institutions, prompting them to download and extract malicious ZIP files containing obfuscated VBS scripts.
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Command and Scripting Interpreter: Visual Basic
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Application Layer Protocol: Web Protocols
Screen Capture
Input Capture: Keylogging
User Execution: Malicious File
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Protect all systems and networks from malicious software
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Management and Access Control
Control ID: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Primary target of Lampion banking trojan with credential theft overlays, compromising financial transactions and customer data through sophisticated phishing campaigns.
Financial Services
High risk from Brazilian banking malware targeting Portuguese organizations, exploiting financial processes and customer authentication systems for credential harvesting.
Government Administration
Frequently impersonated by Lampion attackers mimicking Tax and Customs Authority, creating trust exploitation vectors and potential administrative system compromises.
Automotive
Targeted through impersonation of automotive documentation agencies in phishing campaigns, exposing customer transaction data and administrative processes to compromise.
Sources
- Brazilian Banking Trojan Actively Spreading in Portugalhttps://www.darkreading.com/cyberattacks-data-breaches/brazilian-banking-trojan-spreading-portugalVerified
- Lampion's Portugal-focused phishing campaign delivers multistage malwarehttps://www.acronis.com/en/tru/posts/lampions-portugal-focused-phishing-campaign-delivers-multistage-malware/Verified
- Lampion malware campaign targets users in Portugalhttps://itbrief.co.uk/story/lampion-malware-campaign-targets-users-in-portugalVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the Lampion banking Trojan campaign as it can significantly limit the malware's ability to move laterally, establish command-and-control channels, and exfiltrate sensitive data, thereby reducing the potential blast radius of such attacks.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial compromise may not be directly prevented by CNSF, but subsequent malicious activities could be constrained.
Control: Zero Trust Segmentation
Mitigation: The malware's ability to escalate privileges and establish persistence could be limited by restricting unauthorized inter-workload communications.
Control: East-West Traffic Security
Mitigation: The malware's lateral movement within the network would likely be constrained, reducing its ability to propagate.
Control: Multicloud Visibility & Control
Mitigation: The malware's ability to establish command-and-control channels could be limited, disrupting its communication with external servers.
Control: Egress Security & Policy Enforcement
Mitigation: The exfiltration of sensitive data to external servers would likely be constrained, reducing data loss.
The overall impact of the attack would likely be reduced due to constrained malware activities.
Impact at a Glance
Affected Business Functions
- Online Banking Services
- Customer Account Management
- Financial Transactions Processing
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of customer banking credentials and personal information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Deploy Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the network.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities promptly.
- • Apply Inline IPS (Suricata) to detect and block known exploit patterns and malicious payloads.
- • Ensure Multicloud Visibility & Control to maintain centralized policy enforcement and traffic observability across cloud environments.



