Lampion RAT Malware Hidden in Fake Payment Receipt Emails
Key Takeaways A new phishing campaign is actively distributing the Lampion Remote Access Trojan (RAT) to targets primarily in Portugal. Attackers are leveraging fake payment receipt emails with...
Key Takeaways
- A new phishing campaign is actively distributing the Lampion Remote Access Trojan (RAT) to targets primarily in Portugal.
- Attackers are leveraging fake payment receipt emails with oversized attachments to bypass traditional security measures and evade analysis.
- The Lampion RAT, a Brazilian banking malware, employs a multi-stage infection chain involving ZIP archives, padded HTML and VBS files, and JavaScript.
- The final Lampion RAT payload, a 750MB DLL, grants attackers extensive control over compromised systems, enabling data theft.
Cybercriminals are deploying the Lampion remote access trojan (RAT) through a sophisticated phishing campaign that uses fraudulent payment receipt emails. This operation, predominantly targeting users in Portugal, utilizes large file sizes and multi-stage delivery to circumvent detection and complicate analysis by security researchers.
Table Of Content
The campaign initiates with phishing emails crafted to resemble legitimate financial or administrative correspondence. These messages, designed with convincing business details and urgent language, prompt recipients to open a ZIP attachment masquerading as a payment receipt. This seemingly innocuous action triggers the initial phase of the malware infection, transforming a routine business interaction into a critical security compromise.
Analysis by Acronis researchers pinpointed this activity as a novel Lampion campaign, exhibiting a strong focus on Portuguese users. The findings indicated that an overwhelming 94.6 percent of detections occurred within Portugal, underscoring the attackers’ precision in tailoring their lures, language, and branding for a specific audience. As Acronis said in a report, this targeted approach enhances the credibility of the malicious communications.
Lampion is a well-known Brazilian banking malware family, first documented in 2019 and associated with the ChePro lineage. Despite its Brazilian origins, the operators have consistently targeted Portuguese-speaking victims, employing localized scams to imbue their malicious messages with a high degree of authenticity.
This latest iteration of the Lampion campaign highlights how even older malware families can remain potent when attackers refine their delivery mechanisms. Instead of embedding the entire malicious payload within a single file, the attackers have ingeniously fragmented the infection across multiple stages. This layered approach makes it significantly more challenging for both end-users and security teams to discern the full scope of the attack chain and implement timely defenses.
Hackers Hide 750MB Lampion RAT
The phishing emails leverage the universally recognized and often urgent nature of payment receipts as their primary lure. To enhance credibility, the messages incorporate standard business elements such as confidentiality notices, automated mailbox text, corporate addresses, and social media links, allowing them to seamlessly blend into typical corporate communications.
One observed ZIP attachment, named COMPROVATIVO-JUNHO_OJLWnObxFOyTZkx_01-06-2026_104.zip, contained an HTML document approximately 1.3MB in size. This HTML file was heavily padded with irrelevant code and random strings. This padding technique is a deliberate strategy to hinder inspection and reduce the likelihood of the file matching established detection signatures.
Upon execution, the HTML file presents a deceptive SAPO Transfer page, mimicking a trusted Portuguese online service. This visual masquerade is designed to reassure victims, while hidden JavaScript concurrently retrieves the subsequent stage of the malware in the background without overt alerts.
The downloaded JavaScript is then injected into the webpage and executed discreetly. This multi-layered infection process underscores the critical importance of exercising extreme caution with unexpected attachments, particularly those that create a sense of urgency around invoices, receipts, or financial confirmations.
Following this, the attackers deploy Visual Basic Script (VBS) files, whose filenames continue the payment-themed deception, such as Comprovativo_Junho_15-06-2026-WjGAxGL.vbs. This method of using attachment-based social engineering for initial compromise aligns with common phishing attack vectors, where malicious files remain a prevalent entry point into organizational networks.
These VBS scripts are also inflated with extraneous data. One analyzed file, despite containing only about 22KB of functional code, measured approximately 7MB. This significant file size inflation serves to obscure malicious behavior and complicates both automated and manual security reviews, further aiding in evasion.
750MB RAT Payload
The final VBS component is responsible for conducting victim profiling, gathering system information, and establishing communication with command-and-control (C2) infrastructure to retrieve the ultimate payload. It possesses capabilities to create scheduled tasks, eliminate other VBS files from temporary directories, and generate a unique identifier based on the compromised system’s details.
The malware proceeds to download a Dynamic Link Library (DLL) into a folder named with a timestamp, located within the user’s AppData directory. It employs HTTP range requests to download the file in 10MB segments, reassembling it locally before scheduling its execution via rundll32.
The complete DLL payload is notably large, approximately 750MB. However, this size does not correspond to genuine complexity but rather to extensive junk padding. This tactic is a long-standing characteristic of Lampion malware, specifically designed to impede scanning, transfer, and analysis processes, making detection more difficult for security tools.
Once activated, the DLL executes an exported function named jangadeiro, functioning as the core remote access trojan. This grants attackers unauthorized access to the compromised system, facilitating data theft and posing significant risks to both individuals and organizations.
This campaign is consistent with broader trends of malware operations targeting European banking users through highly localized phishing lures. Recent reports concerning Ousaban phishing PDF attacks illustrate a similar pattern, where attackers combine fake financial documents with scripts and staged payloads to compromise victims in regions like Portugal and Spain.
What You Should Do
- Scrutinize all unexpected payment receipts or financial documents, verifying their legitimacy with the sender through an alternative, trusted communication channel before opening any attachments.
- Implement robust email security solutions with advanced attachment scanning and sandboxing capabilities, understanding that sophisticated malware may employ evasive techniques like geofencing during analysis.
- Monitor for unusually large DLL files within user AppData directories, especially those in timestamp-named folders, as these may indicate a Lampion RAT infection.
- Regularly review scheduled tasks for suspicious entries involving
cmd /c move,rundll32, or VBS files in temporary folders. - Inspect all suspicious outbound network connections, particularly those originating from processes linked to recently opened payment-themed attachments.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 87efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87b |
Phishing email hash |
| SHA-256 | ab46f7c4d3f717bb1e61d2f236917976d2a85be6958ae099fee79ea6e9031e37b |
ZIP attachment hash |
| SHA-256 | 1c101bd1ba134ffbea61f9fac2b7c8fbd13ca113a37944abdc131ef86da92acc |
HTML file hash |
| SHA-256 | 6618bb692fb3f5d7959f8db1fedaaac5e8a36fb901397a008aa2b88874448fd |
Second-stage VBS hash |
| SHA-256 | 036c8f32012abdcb9a389ae9c284da89505e830bca74eb1aa9ea3794b067aab |
Final-stage VBS hash |
| File name | COMPROVATIVO-JUNHO_OJLWnObxFOyTZkx_01-06-2026_104.zip |
Malicious ZIP attachment |
| File name | Comprovativo_Junho_15-06-2026-WjGAxGL.vbs |
Observed second-stage VBS file |
| File name | Comprovativo_Maio_18-05-2026-pXiaBxQ.vbs |
Observed second-stage VBS file |
| Domain | auto-contabilistica.com |
Involved domain |
| Domain | autoridade-contabilistica.org |
Involved domain |
| Domain | autoridade-financeira.com |
Involved domain |
| Domain | fat-contabislitaca.com |
Next-stage downloader domain |
| URL | hxxps://fat-contabislitaca[.]com/js/1898.php |
JavaScript downloader URL |
| C2 URL | hxxp://18.218.184[.]201/03_metal7342/trapezio.php |
Final-stage VBS C2 |
| C2 URL | hxxp://18.222.100[.]142/17_moldura8210/regerem.php |
Final-stage VBS C2 |
| C2 URL | hxxp://18.222.100[.]142/18_prateleira1967/revigore.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.135.194[.]95/09_nsabdo/receado.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.139.85[.]102/17_eudhfj/regerem.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.139.85[.]102/18_vdsyuh/revigore.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.139.85[.]102/20_fjegydk/destravares.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.141.199[.]105/13_ytdshe/reimpresso.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.141.199[.]105/15_rjhsymc/unificador.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.141.199[.]105/16_kdsgyue/raquete.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.144.37[.]134/01_sdneow/fruais.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.144.37[.]134/02_sjdhie/reestruturado.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.144.37[.]134/03_osneops/trapezio.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.148.240[.]228/05_dnwodu/equivaler.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.148.240[.]228/06_sndiwds/galgassem.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.150.134[.]118/05_papel6197/equivaler.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.150.134[.]118/06_couro8254/galgassem.php |
Final-stage VBS C2 |
| C2 URL | hxxp://52.14.160[.]173/10_algodao9148/reunia.php |
Final-stage VBS C2 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.