securityonline.info 7/29/2026, 8:11:27 AM · external

Lampion malware hits Portuguese users via fake SAPO phishing ZIPs

Lampion malware hits Portuguese users via fake SAPO phishing ZIPs
CyberSIXT Evidence Panel
Primary Source acronis.com

THE Lampion malware campaign, tracked by Acronis Threat Research Unit (TRU), primarily targets Portuguese speakers through phishing emails containing ZIP attachments that lead to a fake SAPO file transfer page. The malware is classified as a Brazilian banking trojan and operates using a multistage VBS loader that facilitates remote access and data theft. The campaign is notable for its deceptive techniques, including oversized files designed to hinder malware detection.

Portugal accounts for 94.6% of the detections, with minor spillover into Spain and the UK. Recommendations for detection and prevention include blocking HTML and VBS files in ZIP attachments, alerting on unusually large script files, and monitoring for suspicious tasks and downloads.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline