lampion

First seen
2019-12-01 00:00:00
Malware type
downloader
Last IoC activity
2026-07-21 10:03:41
Profile updated
2026-07-07 14:41:25

Targeted industries: financial-services

Targeted regions: country_code:pt

Context

Malware is delivered by emails, containing links to ZIP files or ZIP attachments. The ZIP contains a VBscript that, when executed, downloads additional files from AWS S3, Google Drive or other cloud hosting services. The downloaded files are encrypted .exe and .dll files. The malware targets banking clients in Portugal.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Vbs.Lampion (report)
  • seguranca-informatica.pt — Trojan Lampion Is Back After 3 Months (report)
  • securityaffairs.co — Hidden C2 Lampion Trojan Release 212 (report)
  • layer8.pt — New%20Lampion%20Banking%20Trojan%20Variant%20In%20The%20Wild (report)
  • research.checkpoint.com — Threat Intelligence News 2019 12 30 (report)
  • seguranca-informatica.pt — The Hidden C2 Lampion Trojan Release 212 Is On The Rise And Using A C2 Server For Two Years (report)
  • seguranca-informatica.pt — Lampion Trojan Disseminated In Portugal Using Covid 19 Template (report)
  • Palo Alto Unit 42 — Single Bit Trap Flag Intel Cpu (report)
  • seguranca-informatica.pt — New Release Of Lampion Trojan Spreads In Portugal With Some Improvements On The Vbs Downloader (report)
  • seguranca-informatica.pt — Targeting Portugal A New Trojan Lampion Has Spread Using Template Emails From The Portuguese Government Finance Tax (report)
  • cofense.com — Lampion Trojan Utilizes New Delivery Through Cloud Based Sharing (report)

External references