
Fake Claude App and Alert Apps Drive New Scams
This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…
Researchers report that the Lampion banking Trojan is spreading in Portugal through phishing emails that impersonate legitimate private-sector entities. Victims who follow the lure end up with a credential-stealing remote-access tool (RAT) that can overlay fake login screens on banking sites to capture credentials.
The Lampion banking Trojan has been active against Portuguese organizations since 2019, and researchers report a new phishing campaign still using this malware. The lure impersonates private-sector entities, with an automotive documentation agency given as an example. Victims receive an email that asks them to open a file or follow a link to complete some kind of business process or documentation request. Following the lure leads to installation of a credential-stealing remote-access tool (RAT).
Once installed, the RAT does not simply log keystrokes. It uses overlays, fake login screens placed on top of legitimate banking websites, to capture credentials as the victim attempts to log in. This means the visible banking site may look normal at first glance, but the login prompt itself is attacker-controlled.
This campaign works because it leans on ordinary business communication patterns rather than obviously suspicious content. An email referencing documentation or a process tied to a private-sector agency does not immediately look like a scam, especially to finance and accounting staff who regularly handle paperwork from outside vendors or agencies. The credential theft also happens in two stages: the phishing email delivers the RAT, and the actual theft occurs later when the victim logs into their bank, which separates the initial compromise from the moment credentials are stolen and makes the connection harder to notice.
Employees, especially those in finance and accounting or anyone with online banking access, should verify unexpected business-process emails through a known, trusted contact method rather than acting on the message directly. Staff should also be trained to pause and report anything unusual at a banking login screen before entering credentials, since this campaign specifically relies on convincing overlay screens to succeed. Finally, organizations should reinforce that phishing can lead to more than a stolen password, in this case a fully installed RAT, so quick reporting of any suspicious click or file opening is critical to limiting damage.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Lampion is a banking Trojan that has targeted Portuguese organizations since 2019 and remains active through phishing campaigns impersonating private-sector entities.
After a victim is tricked into opening a malicious file or link, Lampion deploys a credential-stealing RAT that overlays fake login screens on banking websites to capture usernames and passwords.
The campaign impersonates private-sector entities, with an automotive documentation agency given as an example lure.
Finance and accounting staff, along with any employee who has online banking access, are the primary targets since the end goal is capturing banking credentials.
You get an email: “Subject: Action required – documentation request” from an automotive documentation agency you’ve never used. This is Lampion phishing in Portugal. If you click the file or link, it quietly installs a credential-stealing RAT that waits for your online banking. Here’s the nasty part: when you visit your banking site, Lampion overlays a fake login screen on top of the real one. You think it’s your bank; it’s actually stealing your credentials. If you ever get an unexpected agency email asking you to open a file or link, pause, don’t click. Call or message the agency or our helpdesk using a known contact to confirm first.

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to…