Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Portugal-focused phishing campaign delivers multistage malware

87efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87b

TLP:CLEAR
Active

SHA-256 Hash

Description

An active Lampion malware campaign has been identified targeting Portuguese users through phishing emails that impersonate financial and administrative communications. Lampion, a Brazilian banking malware derived from the ChePro lineage, delivers initial payloads via ZIP archives containing heavily obfuscated HTML files designed to evade detection. The HTML stage retrieves additional scripts from attacker-controlled infrastructure, initiating a multistage VBS infection chain. Each stage employs extensive obfuscation techniques including junk code, encrypted strings, and dynamically generated scripts that inflate file sizes while concealing core functionality. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis. Telemetry shows 94.6% of detections concentrated in Portugal, confirming this is a highly targeted threat focused on Portuguese-speaking victims.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Portugal-focused phishing campaign delivers multistage malware
Pattern Type
STIX
Confidence
75%
Valid From
Jul 23, 2026 14:00
Total Sightings
0
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 87efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87b

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.