Lampion's Portugal-focused phishing campaign delivers multistage malware
ID: 70080f0b-f931-52f9-8fef-5017bf6905bd
STIX ID: report--70080f0b-f931-52f9-8fef-5017bf6905bd
Feed Name: TRU Security by Acronis
Acronis TRU documents an active, targeted Lampion malware campaign abusing Portuguese-language phishing lures and fake SAPO-branded HTML attachments to deliver a multistage infection (obfuscated HTML → downloader → VBS stages → large DLL RAT executed via rundll32). The campaign uses heavy junk-padding and obfuscation, chunked HTTP Range downloads, scheduled tasks for persistence, and telemetry showing ~94.6% of detections in Portugal; the report includes ATT&CK mappings, IoCs (file hashes, domains, ephemeral IP C2 hosts) and practical detection/hunting indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
