Lampion Banking Trojan (ChePro Lineage) Multistage Phishing/Evasion Campaign Targets Portugal — Threadlinqs Intelligence
As of 2026-07-22, Lampion Banking Trojan (ChePro Lineage) Multistage Phishing/Evasion Campaign Targets Portugal is a medium-severity malware threat attributed to Lampion, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1619 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
Attribution: Lampion · FINANCIAL
Acronis Threat Research Unit identified an active phishing campaign delivering the Lampion (ChePro-lineage) Brazilian banking RAT to Portuguese-speaking users, primarily in Portugal (94.6% of
Lampion is a Brazilian banking trojan derived from the ChePro malware lineage (Trojan-Banker.Win32.ChePro, first observed in Russia in October 2012, historically concentrated in Brazil and Portugal due to shared language). Lampion itself was first publicly documented on 2019-12-26 by Segurança Informática, spreading via phishing emails templated on Portuguese Government Finance & Tax communications. The family has remained active and continuously refined its delivery tradecraft through 2020-2025, including a Unit 42-documented resurgence (late 2024-early 2025) against Portuguese government, finance, and transportation organizations using ClickFix-style PowerShell lures and C2 infrastructure reuse tied back to prior Lampion infections.
The campaign profiled here (Acronis TRU, published 2026-07-21) begins with a phishing email carrying a password-protected or plain ZIP archive impersonating financial/administrative correspondence. Inside is an HTML file artificially inflated to roughly 1.3 MB with random junk content and padding, rendering a fake "SAPO Transfer" portal page. Embedded JavaScript on this page retrieves a second-stage payload from an encrypted URL and dynamically injects/executes it. Stage 2 is an obfuscated VBS downloader roughly 7 MB in size but containing only ~22 KB of functional code (the remainder is junk-code padding used to defeat static/AV signature analysis); it writes a further downloader script to a temp directory and registers a Windows Task Scheduler task to launch the next stage. Stage 3 is a ~1,000-line VBS component that enforces single-instance execution via WMI process checks, fingerprints the victim (username, hostname, BIOS, motherboard, and GPU identifiers) to build a persistent victim ID, polls command-and-control infrastructure for a payload URL, and retrieves the final payload in 10 MB HTTP range-request chunks reassembled via an ADODB.Stream object — a technique that defeats network content-inspection tools expecting a single monolithic download. Intermediate VBS files self-delete after each stage, and scheduled tasks relocate/rename downloaded artifacts and can self-restart the chain roughly every 5 minutes if a stage fails.
The final payload is a DLL roughly 750 KB of genuine code padded to a much larger on-disk footprint (researchers describe the resulting artifact size, ~750 MB in some reporting of the padded form, as being driven entirely by junk padding rather than functional complexity), deployed into a timestamp-named folder under the user's AppData directory and executed via `rundll32.exe`, invoking an exported function named "jangadeiro" (Portuguese for the fisherman who pilots a jangada raft — consistent with the malware's Brazilian cultural origin). This DLL is the operational RAT component, providing remote access, screen/window monitoring typical of Latin American/Iberian banking trojans, credential and banking-session interception, and data exfiltration back to attacker infrastructure.
Operators use geofencing/victim-tracking controls so that payloads are only delivered to victims matching expected geography/locale, restricting analysis by researchers outside the target regions and explaining the concentrated 94.6% Portugal detection rate. C2 hosts are described as time-bound and potentially reassigned, consistent with Lampion's historical use of disposable or rotated infrastructure and, in earlier campaigns, abuse of legitimate cloud hosting (AWS S3, Google Drive) for payload staging.
Target sectors: financial services, government administration, accounting, transport, general consumer retail banking customers
Target regions: portugal, spain, united kingdom
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1566, T1566.001, T1204.002, T1059.005, T1059.007, T1218.011, T1053.005, T1218.011, T1027, T1027.001