THE Lampion malware campaign, tracked by Acronis Threat Research Unit (TRU), primarily targets Portuguese speakers through phishing emails containing ZIP attachments that lead to a fake SAPO file transfer page. The malware is classified as a Brazilian banking trojan and operates using a multistage VBS loader that facilitates remote access and data theft. The campaign is notable for its deceptive techniques, including oversized files designed to hinder malware detection.
Portugal accounts for 94.6% of the detections, with minor spillover into Spain and the UK. Recommendations for detection and prevention include blocking HTML and VBS files in ZIP attachments, alerting on unusually large script files, and monitoring for suspicious tasks and downloads.