Acronis TRU uncovered an active Lampion campaign that uses Portuguese-language phishing emails, fake financial documents, and a staged infection chain to target users in Portugal. The malware delivers oversized, heavily obfuscated HTML and VBS files that ultimately install a RAT via rundll32 and a DLL payload hosted on attacker-controlled infrastructure. #Lampion #SAPO #AlticePortugal
Keypoints
- Campaigns are highly focused on Portugal, accounting for 94.6% of detections, with smaller spillover in Spain and the United Kingdom.
- Attackers use phishing emails that impersonate payment receipts and other administrative or financial communications to lure victims.
- The initial payload is a ZIP archive containing a heavily obfuscated HTML file that is artificially inflated to hinder analysis and detection.
- The HTML stage abuses SAPO branding and downloads the next-stage payload from attacker-controlled infrastructure.
- Subsequent VBS stages are also obfuscated and use scheduled tasks, %TEMP%, and %APPDATA% to drive execution and persistence.
- The final stage downloads a large DLL, executes it with rundll32, and turns the payload into the main RAT component for remote access and data exfiltration.
- Acronis notes that the campaign is using geofencing or victim-tracking, making the next-stage payload difficult to retrieve outside a live infection chain.
MITRE Techniques
- [T1566.001 ] Spearphishing Attachment – The attack starts with a ZIP attachment delivering the lure and initial payload (‘ZIP-attached HTML lure’).
- [T1204.002 ] User Execution – Victims must open the malicious attachment/file to trigger the infection chain (‘encourage the recipient to open an attachment’).
- [T1027 ] Obfuscated Files or Information – Multiple stages use junk code, encrypted strings, and dynamically generated scripts to hide functionality (‘heavily obfuscated’).
- [T1027.001 ] Binary Padding – Files are artificially inflated with nonfunctional content, including a ~750 MB DLL and oversized HTML/VBS files (‘artificially inflated’, ‘junk padding’).
- [T1059.007 ] JavaScript – The rendered HTML page uses embedded JavaScript to retrieve and inject the next-stage loader (‘initiates the retrieval of the next-stage payload’).
- [T1059.005 ] Visual Basic – The campaign uses multistage VBS scripts for downloader creation, task creation, and final payload orchestration (‘second-stage VBS’, ‘final stage’).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task – The malware creates scheduled tasks to download, move, and restart components (‘Creates a scheduled task’, ‘delayed self-restart task’).
- [T1105 ] Ingress Tool Transfer – The final stage downloads the payload in HTTP Range chunks and reconstructs it locally (‘Downloads the payload in 10MB HTTP Range chunks’).
- [T1218.011 ] System Binary Proxy Execution: Rundll32 – The downloaded DLL is executed through rundll32 using the export jangadeiro (‘executed via rundll32, invoking the exported function jangadeiro’).
- [T1071.001 ] Application Layer Protocol: Web Protocols – Command-and-control and payload retrieval occur over HTTP-based web traffic (‘polls a C2 URL’, ‘HTTP Range’).
- [T1518.001 ] Security Software Discovery – The beacon includes the AV product display name as part of victim profiling (‘Sends a Base64 analytics beacon … AV product display name’).
- [T1497 ] Virtualization/Sandbox Evasion – The campaign uses environmental checks and likely geofencing to avoid analysis (‘strict geofencing and / or victim-tracking mechanisms’).
Indicators of Compromise
- [SHA-256 ] Phishing email and attachment samples – 87efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87bab46f7c4d3f717bb1e61d2f236917976d2a85be6958ae099fee79ea6e9031e37, b1c101bd1ba134ffbea61f9fac2b7c8fbd13ca113a37944abdc131ef86da92acc6618bb692fb3f5d7959f8db1fedaaac5e8a36fb901397a008aa2b88874448fd
- [SHA-256 ] HTML and VBS payloads – 036c8f32012abdcb9a389ae9c284da89505e830bca74eb1aa9ea3794b067aab6d25d32478ae67403484a309591b6409224d26ca3d094c5ccd8428ebef7efcfd1643c0093baec45952a46b0210f7a6f8fb26883b396b66f1cb609c5b55e6dae1e050e84d134a32ed7c4885a9d57ce37f8ae5f910960b67e2156941961bd5781ba, 7ad89fb0a4a5449a381b8f540238193019673adc7cfb1c008dcd14a7458915511bd347ce5deee3d783a038e2d2d224bc30cc074e0471a3897c5409ce99816dc9
- [SHA-256 ] Final-stage VBS payload – 1541c23f34eb05dfcbede3830741427681d719cee1dfd397a2c04110e0fa81b2fe769fd85a7440751e1508614c8d9ef0de00bece803329bf3318ff863a146216
- [Domain ] Attacker-controlled infrastructure used for downloads and staging – auto-contabilistica.com, autoridade-contabilistica.org
- [Domain ] Additional staging and C2 infrastructure – autoridade-financeira.com, fat-contabislitaca.com
- [IP/URL ] Defanged C2 hosts for the final VBS stage – hxxp://18.218.184.201/03_metal7342/trapezio.php, hxxp://18.222.100.142/17_moldura8210/regerem.php, and other 14 items
- [File names ] Malicious attachments and scripts – COMPROVATIVO-JUNHO_OJLWnObxFOyTZkx_01-06-2026_104.zip, Comprovativo_Junho_15-06-2026-WjGAxGL.vbs, and Comprovativo_Maio_18-05-2026-pXiaBxQ.vbs