Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
InfoStealer Logs Fuel Massive Cloud Data Breaches
July 24, 2026
Lampion RAT Malware Hidden in Fake Payment Receipt Emails
July 24, 2026
Google Chrome Emergency Update Patches Four High-Severity Flaws
July 24, 2026
Home/CyberSecurity News/Lampion RAT Malware Hidden in Fake Payment Receipt Emails
CyberSecurity News

Lampion RAT Malware Hidden in Fake Payment Receipt Emails

Key Takeaways A new phishing campaign is actively distributing the Lampion Remote Access Trojan (RAT) to targets primarily in Portugal. Attackers are leveraging fake payment receipt emails with...

Emy Elsamnoudy
Emy Elsamnoudy
July 24, 2026 5 Min Read
2 0

Key Takeaways

  • A new phishing campaign is actively distributing the Lampion Remote Access Trojan (RAT) to targets primarily in Portugal.
  • Attackers are leveraging fake payment receipt emails with oversized attachments to bypass traditional security measures and evade analysis.
  • The Lampion RAT, a Brazilian banking malware, employs a multi-stage infection chain involving ZIP archives, padded HTML and VBS files, and JavaScript.
  • The final Lampion RAT payload, a 750MB DLL, grants attackers extensive control over compromised systems, enabling data theft.

Cybercriminals are deploying the Lampion remote access trojan (RAT) through a sophisticated phishing campaign that uses fraudulent payment receipt emails. This operation, predominantly targeting users in Portugal, utilizes large file sizes and multi-stage delivery to circumvent detection and complicate analysis by security researchers.

Table Of Content

  • Key Takeaways
  • Hackers Hide 750MB Lampion RAT
  • 750MB RAT Payload
  • What You Should Do

The campaign initiates with phishing emails crafted to resemble legitimate financial or administrative correspondence. These messages, designed with convincing business details and urgent language, prompt recipients to open a ZIP attachment masquerading as a payment receipt. This seemingly innocuous action triggers the initial phase of the malware infection, transforming a routine business interaction into a critical security compromise.

Analysis by Acronis researchers pinpointed this activity as a novel Lampion campaign, exhibiting a strong focus on Portuguese users. The findings indicated that an overwhelming 94.6 percent of detections occurred within Portugal, underscoring the attackers’ precision in tailoring their lures, language, and branding for a specific audience. As Acronis said in a report, this targeted approach enhances the credibility of the malicious communications.

Lampion is a well-known Brazilian banking malware family, first documented in 2019 and associated with the ChePro lineage. Despite its Brazilian origins, the operators have consistently targeted Portuguese-speaking victims, employing localized scams to imbue their malicious messages with a high degree of authenticity.

This latest iteration of the Lampion campaign highlights how even older malware families can remain potent when attackers refine their delivery mechanisms. Instead of embedding the entire malicious payload within a single file, the attackers have ingeniously fragmented the infection across multiple stages. This layered approach makes it significantly more challenging for both end-users and security teams to discern the full scope of the attack chain and implement timely defenses.

Hackers Hide 750MB Lampion RAT

The phishing emails leverage the universally recognized and often urgent nature of payment receipts as their primary lure. To enhance credibility, the messages incorporate standard business elements such as confidentiality notices, automated mailbox text, corporate addresses, and social media links, allowing them to seamlessly blend into typical corporate communications.

One observed ZIP attachment, named COMPROVATIVO-JUNHO_OJLWnObxFOyTZkx_01-06-2026_104.zip, contained an HTML document approximately 1.3MB in size. This HTML file was heavily padded with irrelevant code and random strings. This padding technique is a deliberate strategy to hinder inspection and reduce the likelihood of the file matching established detection signatures.

Upon execution, the HTML file presents a deceptive SAPO Transfer page, mimicking a trusted Portuguese online service. This visual masquerade is designed to reassure victims, while hidden JavaScript concurrently retrieves the subsequent stage of the malware in the background without overt alerts.

The downloaded JavaScript is then injected into the webpage and executed discreetly. This multi-layered infection process underscores the critical importance of exercising extreme caution with unexpected attachments, particularly those that create a sense of urgency around invoices, receipts, or financial confirmations.

Following this, the attackers deploy Visual Basic Script (VBS) files, whose filenames continue the payment-themed deception, such as Comprovativo_Junho_15-06-2026-WjGAxGL.vbs. This method of using attachment-based social engineering for initial compromise aligns with common phishing attack vectors, where malicious files remain a prevalent entry point into organizational networks.

These VBS scripts are also inflated with extraneous data. One analyzed file, despite containing only about 22KB of functional code, measured approximately 7MB. This significant file size inflation serves to obscure malicious behavior and complicates both automated and manual security reviews, further aiding in evasion.

750MB RAT Payload

The final VBS component is responsible for conducting victim profiling, gathering system information, and establishing communication with command-and-control (C2) infrastructure to retrieve the ultimate payload. It possesses capabilities to create scheduled tasks, eliminate other VBS files from temporary directories, and generate a unique identifier based on the compromised system’s details.

The malware proceeds to download a Dynamic Link Library (DLL) into a folder named with a timestamp, located within the user’s AppData directory. It employs HTTP range requests to download the file in 10MB segments, reassembling it locally before scheduling its execution via rundll32.

The complete DLL payload is notably large, approximately 750MB. However, this size does not correspond to genuine complexity but rather to extensive junk padding. This tactic is a long-standing characteristic of Lampion malware, specifically designed to impede scanning, transfer, and analysis processes, making detection more difficult for security tools.

Once activated, the DLL executes an exported function named jangadeiro, functioning as the core remote access trojan. This grants attackers unauthorized access to the compromised system, facilitating data theft and posing significant risks to both individuals and organizations.

This campaign is consistent with broader trends of malware operations targeting European banking users through highly localized phishing lures. Recent reports concerning Ousaban phishing PDF attacks illustrate a similar pattern, where attackers combine fake financial documents with scripts and staged payloads to compromise victims in regions like Portugal and Spain.

What You Should Do

  • Scrutinize all unexpected payment receipts or financial documents, verifying their legitimacy with the sender through an alternative, trusted communication channel before opening any attachments.
  • Implement robust email security solutions with advanced attachment scanning and sandboxing capabilities, understanding that sophisticated malware may employ evasive techniques like geofencing during analysis.
  • Monitor for unusually large DLL files within user AppData directories, especially those in timestamp-named folders, as these may indicate a Lampion RAT infection.
  • Regularly review scheduled tasks for suspicious entries involving cmd /c move, rundll32, or VBS files in temporary folders.
  • Inspect all suspicious outbound network connections, particularly those originating from processes linked to recently opened payment-themed attachments.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 87efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87b Phishing email hash
SHA-256 ab46f7c4d3f717bb1e61d2f236917976d2a85be6958ae099fee79ea6e9031e37b ZIP attachment hash
SHA-256 1c101bd1ba134ffbea61f9fac2b7c8fbd13ca113a37944abdc131ef86da92acc HTML file hash
SHA-256 6618bb692fb3f5d7959f8db1fedaaac5e8a36fb901397a008aa2b88874448fd Second-stage VBS hash
SHA-256 036c8f32012abdcb9a389ae9c284da89505e830bca74eb1aa9ea3794b067aab Final-stage VBS hash
File name COMPROVATIVO-JUNHO_OJLWnObxFOyTZkx_01-06-2026_104.zip Malicious ZIP attachment
File name Comprovativo_Junho_15-06-2026-WjGAxGL.vbs Observed second-stage VBS file
File name Comprovativo_Maio_18-05-2026-pXiaBxQ.vbs Observed second-stage VBS file
Domain auto-contabilistica.com Involved domain
Domain autoridade-contabilistica.org Involved domain
Domain autoridade-financeira.com Involved domain
Domain fat-contabislitaca.com Next-stage downloader domain
URL hxxps://fat-contabislitaca[.]com/js/1898.php JavaScript downloader URL
C2 URL hxxp://18.218.184[.]201/03_metal7342/trapezio.php Final-stage VBS C2
C2 URL hxxp://18.222.100[.]142/17_moldura8210/regerem.php Final-stage VBS C2
C2 URL hxxp://18.222.100[.]142/18_prateleira1967/revigore.php Final-stage VBS C2
C2 URL hxxp://3.135.194[.]95/09_nsabdo/receado.php Final-stage VBS C2
C2 URL hxxp://3.139.85[.]102/17_eudhfj/regerem.php Final-stage VBS C2
C2 URL hxxp://3.139.85[.]102/18_vdsyuh/revigore.php Final-stage VBS C2
C2 URL hxxp://3.139.85[.]102/20_fjegydk/destravares.php Final-stage VBS C2
C2 URL hxxp://3.141.199[.]105/13_ytdshe/reimpresso.php Final-stage VBS C2
C2 URL hxxp://3.141.199[.]105/15_rjhsymc/unificador.php Final-stage VBS C2
C2 URL hxxp://3.141.199[.]105/16_kdsgyue/raquete.php Final-stage VBS C2
C2 URL hxxp://3.144.37[.]134/01_sdneow/fruais.php Final-stage VBS C2
C2 URL hxxp://3.144.37[.]134/02_sjdhie/reestruturado.php Final-stage VBS C2
C2 URL hxxp://3.144.37[.]134/03_osneops/trapezio.php Final-stage VBS C2
C2 URL hxxp://3.148.240[.]228/05_dnwodu/equivaler.php Final-stage VBS C2
C2 URL hxxp://3.148.240[.]228/06_sndiwds/galgassem.php Final-stage VBS C2
C2 URL hxxp://3.150.134[.]118/05_papel6197/equivaler.php Final-stage VBS C2
C2 URL hxxp://3.150.134[.]118/06_couro8254/galgassem.php Final-stage VBS C2
C2 URL hxxp://52.14.160[.]173/10_algodao9148/reunia.php Final-stage VBS C2

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Google Chrome Emergency Update Patches Four High-Severity Flaws

Next Post

InfoStealer Logs Fuel Massive Cloud Data Breaches

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Russian Hackers Exploit Critical Zimbra Zero-Day to Steal Emails
July 24, 2026
Decathlon Investigates Alleged Breach of 160 Million Customer Records
July 24, 2026
Critical RubyGems Vulnerabilities Let Attackers Mine Monero and Spread via SSH
July 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us