Lampion Phishing Hits Portugal With Fake Brands

About DFIR · Medium sophistication
Last updated July 30, 2026

Researchers report that the Lampion banking Trojan is spreading in Portugal through phishing emails that impersonate legitimate private-sector entities. Victims who follow the lure end up with a credential-stealing remote-access tool (RAT) that can overlay fake login screens on banking sites to capture credentials.

How the attack worked

The Lampion banking Trojan has been active against Portuguese organizations since 2019, and researchers report a new phishing campaign still using this malware. The lure impersonates private-sector entities, with an automotive documentation agency given as an example. Victims receive an email that asks them to open a file or follow a link to complete some kind of business process or documentation request. Following the lure leads to installation of a credential-stealing remote-access tool (RAT).

Once installed, the RAT does not simply log keystrokes. It uses overlays, fake login screens placed on top of legitimate banking websites, to capture credentials as the victim attempts to log in. This means the visible banking site may look normal at first glance, but the login prompt itself is attacker-controlled.

Why it succeeded

This campaign works because it leans on ordinary business communication patterns rather than obviously suspicious content. An email referencing documentation or a process tied to a private-sector agency does not immediately look like a scam, especially to finance and accounting staff who regularly handle paperwork from outside vendors or agencies. The credential theft also happens in two stages: the phishing email delivers the RAT, and the actual theft occurs later when the victim logs into their bank, which separates the initial compromise from the moment credentials are stolen and makes the connection harder to notice.

What to watch for

  • Unexpected emails claiming to be from a business agency or documentation provider you do not regularly work with
  • Messages that push you to open a file or click through a link to proceed with some process
  • Banking site login prompts or overlays that look unusual, mismatched, or unfamiliar compared to normal login screens
  • Any sign of unexpected software installation or activity following a suspicious email

How to build resistance

Employees, especially those in finance and accounting or anyone with online banking access, should verify unexpected business-process emails through a known, trusted contact method rather than acting on the message directly. Staff should also be trained to pause and report anything unusual at a banking login screen before entering credentials, since this campaign specifically relies on convincing overlay screens to succeed. Finally, organizations should reinforce that phishing can lead to more than a stolen password, in this case a fully installed RAT, so quick reporting of any suspicious click or file opening is critical to limiting damage.

Key findings

  • Lampion remains active in Portugal via a new phishing campaign.
  • The campaign impersonates private-sector entities (example given: an automotive documentation agency).
  • The end goal is to deploy a credential-stealing RAT.
  • The RAT uses overlays (fake login screens) on banking websites to capture user credentials.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, All employees (general phishing awareness).
  • Affected industries: Finance/Banking, Private-sector businesses (impersonated brands), Portuguese organizations (multi-industry).
  • Attack channels: email.
  • Impersonated: An automotive documentation agency (private-sector entity).

Red flags to watch for

  • Unexpected email claiming to be a business agency you don’t regularly work with
  • Pushes you to open a file/click a link to proceed
  • Banking site shows an unusual ‘login’ prompt or overlay that doesn’t look right
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Lampion banking Trojan?

Lampion is a banking Trojan that has targeted Portuguese organizations since 2019 and remains active through phishing campaigns impersonating private-sector entities.

How does Lampion steal banking credentials?

After a victim is tricked into opening a malicious file or link, Lampion deploys a credential-stealing RAT that overlays fake login screens on banking websites to capture usernames and passwords.

Who is being impersonated in this campaign?

The campaign impersonates private-sector entities, with an automotive documentation agency given as an example lure.

Who should be most concerned about this campaign?

Finance and accounting staff, along with any employee who has online banking access, are the primary targets since the end goal is capturing banking credentials.

Read the video transcript

You get an email: “Subject: Action required – documentation request” from an automotive documentation agency you’ve never used. This is Lampion phishing in Portugal. If you click the file or link, it quietly installs a credential-stealing RAT that waits for your online banking. Here’s the nasty part: when you visit your banking site, Lampion overlays a fake login screen on top of the real one. You think it’s your bank; it’s actually stealing your credentials. If you ever get an unexpected agency email asking you to open a file or link, pause, don’t click. Call or message the agency or our helpdesk using a known contact to confirm first.

Similar attacks