From Brazil with Love: New Tactics from Lampion

Oct. 31, 2025, 11:38 a.m.

Description

This analysis details a long-running spam campaign by a Brazilian group known for using the Lampion banking trojan. The campaign, active since at least 2019, has evolved its infection chain and components. Key updates include the use of email attachments instead of links, cloud services for ephemeral infrastructure, and ClickFix lures for initial compromise. The infection process involves multiple stages of obfuscated Visual Basic scripts, culminating in the deployment of an updated Lampion Stealer. The threat actors demonstrate sophisticated tactics, including IP blacklisting and the use of large file sizes to hinder analysis. The malicious infrastructure is distributed across multiple cloud providers and shows frequent changes in some components while maintaining long-term stability in others. The campaign's persistence and evolution highlight the group's dedication to stealth and evasion techniques.

Date

  • Created: Oct. 31, 2025, 9:33 a.m.
  • Published: Oct. 31, 2025, 9:33 a.m.
  • Modified: Oct. 31, 2025, 11:38 a.m.

Indicators

  • portaldasfinancas.org
  • portaldasfinancas-pt.org
  • portaldasfinancas-at.com
  • portal-das-financas-pt.org
  • portal-das-financas-pt.com
  • indebt-faturas.com
  • fat-doc-online.com
  • autoridadetributaria-pt.org
  • autoridadetributaria.org
  • autoridade-tributaria.org
  • autoridade-tributaria-pt.com
  • autoridade-tributaria-pt.org
  • atportal-das-financas.com
  • autoridade-tributaria-gov.com
  • at-portaldasfinancas.org
  • at-portaldasfinancas.com
  • at-portaldasfinancas-pt.org
  • at-portaldasfinancas-pt.com
  • at-portal-das-financas.com
  • autoridade-tributaria.com

Attack Patterns

  • Lampion Stealer
  • Lampion
  • Lampion

Additional Informations

  • Finance
  • Brazil