Cybercriminals are deploying a sophisticated phishing campaign targeting Portuguese users by embedding the Lampion Remote Access Trojan (RAT) within seemingly legitimate payment receipt emails. This method leverages oversized files and multi-stage infection chains to evade detection and analysis.
The attack initiates with emails that mimic standard financial communications, urging recipients to open an attached ZIP file purportedly containing a payment receipt. Upon extraction, the ZIP file reveals an HTML document, which, when opened, displays a counterfeit SAPO Transfer page—a trusted Portuguese online service. Unbeknownst to the user, this page executes hidden JavaScript code that downloads and runs additional malicious scripts, culminating in the deployment of the Lampion RAT.
Security researchers have observed that 94.6% of detections related to this campaign are in Portugal, indicating a highly targeted approach. The Lampion malware, first identified in 2019 and linked to the Brazilian ChePro lineage, has a history of focusing on Portuguese-speaking victims. The current campaign underscores the adaptability of threat actors in refining their tactics to enhance the effectiveness of their attacks.
To mitigate the risk of such infections, users are advised to exercise caution with unsolicited emails, especially those containing attachments or links. Verifying the authenticity of the sender and the content before interacting with such emails is crucial. Additionally, maintaining up-to-date security software and educating users about phishing tactics can significantly reduce the likelihood of successful attacks.
This campaign highlights the evolving nature of cyber threats, where attackers continuously adapt their methods to bypass security measures. Organizations must remain vigilant and proactive in their cybersecurity practices to protect against such sophisticated attacks.