Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload
ID: f50b4bbf-f700-5033-8c68-ecd372579756
STIX ID: report--f50b4bbf-f700-5033-8c68-ecd372579756
Feed Name: GBHackers
A targeted Lampion malware campaign is abusing Portuguese-language financial phishing emails and a spoofed SAPO transfer interface to deliver a multi-stage infection: oversized ZIP-delivered HTML that fetches obfuscated JavaScript, large VBS downloaders that establish persistence, and a DLL-based remote access trojan reassembled via HTTP range requests. The report includes technical analysis of obfuscation and anti-analysis padding, observed C2 infrastructure, multiple SHA-256 IoCs, and telemetry showing the campaign is highly concentrated in Portugal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
