A long-standing Brazilian banking Trojan known as Lampion is actively targeting organizations in Portugal. This malware, originating from Brazil, has been in circulation since 2019 and continues to exploit the linguistic commonality between Brazil and Portugal. The Trojan is primarily spread through phishing emails that impersonate various financial or administrative bodies, warning recipients of fictitious financial issues. These emails appear legitimate, complete with authentic branding and confidentiality notices, which lure victims into downloading a zip file. This file, when extracted, initiates a sequence of events that mimic a well-known Portuguese internet portal, SAPO, while setting up a backdoor for the attackers. The malware employs obfuscation techniques to evade detection and proceeds to establish a connection with a remote command-and-control server. Ultimately, it installs a dynamic link library that acts as a remote access Trojan, allowing attackers to steal credentials from Portuguese banking sites and gather data on the victim's machine and browser.

Acronis researchers, including senior researcher Jozsef Gegeny, have noted that the techniques used by Lampion have remained largely unchanged since its inception. The attackers find no incentive to innovate as long as these methods continue to yield results. The campaign is highly focused on Portugal, with over 96 percent of attacks occurring there, and some isolated attempts in Spain and England. The attackers use geofencing to ensure their efforts are concentrated on Portuguese-speaking regions, taking advantage of the close linguistic ties between Brazil and Portugal.

Santiago Pontrioli, a threat intelligence research lead at Acronis, highlights that Brazilian cybercriminals prefer targeting countries that share their language, such as Portugal, to avoid local law enforcement scrutiny. This strategic choice also complicates international cooperation in pursuing these criminals. A recent survey by Marsh Risk indicates that cyberattacks have become the foremost risk to Portuguese organizations, surpassing traditional concerns like political and social instability. With Brazil's robust cybercriminal infrastructure and Portugal's linguistic vulnerability, the country remains an attractive target for these malicious actors.