A Six-Year-Old Brazilian Bank Fraud Tool Is Still Emptying Portuguese Accounts
The Lampion banking trojan has barely changed since 2019. It doesn't need to. Portugal keeps falling for it.

Key points
- Lampion, a banking malware first spotted in late 2019, is still running active attacks against Portuguese organisations in 2025.
- Researchers at cybersecurity firm Acronis identified a new campaign in which criminals impersonate private Portuguese businesses, including an automotive documentation agency, to trick victims.
- Around 96.4% of recent Lampion attacks hit Portugal specifically, with a small number reaching Spain and the United Kingdom.
- Brazilian criminals deliberately target Portugal, a country that shares their language, because cross-border policing is slower and harder to coordinate.
- Risk management firm Marsh Risk found that cyberattacks became the number one business risk for Portuguese companies in 2026, the first time in twelve years cyber topped that list.
Some malware gets retired. Lampion just keeps cashing in.
First flagged by security researchers around the 2019 holiday season, Lampion is a banking trojan, meaning software criminals install secretly on a victim's computer so it can steal their online banking credentials. It was built in Brazil, a country with one of the most active cybercrime scenes on the planet. For six years it has been pointed almost exclusively at Portugal, and according to new research from Acronis, it is still running today in a form that would look familiar to anyone who analysed it back when it first appeared.
How does the attack actually work?
Victims get a convincing fake email. That is where every Lampion attack has started, and that has not changed.
In the campaigns Acronis observed, criminals sent emails pretending to be Portuguese businesses, including an automotive documentation agency. The messages warned recipients about a pending financial or administrative issue and came complete with real brand logos, a confidentiality notice, and a fake email signature with social media links. Everything looked legitimate.
Clicking the attachment downloads a zip file, which is a compressed folder of files. Opening it triggers a webpage that mimics SAPO, Portugal's best-known internet portal, to look normal to the victim. Behind that distraction, the software installs itself quietly, sets up a scheduled task so it restarts automatically, and calls home to a remote server controlled by the criminals.
The end result is a piece of code sitting on the victim's machine that watches for visits to Portuguese banking websites. When the victim logs in, Lampion throws a fake overlay, basically a transparent fake screen, over the real banking page and captures whatever the victim types: usernames, passwords, account details.
| Detail | Fact |
|---|---|
| First discovered | Late 2019 |
| Current activity | Confirmed 2025 (Acronis) |
| Primary target country | Portugal (96.4% of attacks) |
| Other affected countries | Spain, United Kingdom |
| Origin | Brazil |
| Attack starting point | Phishing email with fake receipt or notice |
Why does Portugal keep getting hit?
Shared language, weaker cross-border policing. Simple as that.
Portugal is the largest Portuguese-speaking country in Europe. Brazilian criminals can write convincing phishing emails without a translator, and their fake documents look native because they are. Acronis threat intelligence lead Santiago Pontrioli recalls a talk he attended in São Paulo where Brazilian criminals explained their own logic directly: target outside Brazil so local police can't easily act, because the moment you involve two countries you need Interpol, and Interpol takes time.
The strategy works. Marsh Risk found that cyberattacks became the single biggest risk reported by Portuguese companies in 2026, beating out political instability for the first time in twelve years of that survey.
Acronics senior researcher Jozsef Gegeny put it plainly: the attackers keep using the same techniques because the same techniques keep making money. There is no business case for redesigning something profitable.
The failure mode here is not a sophisticated zero-day, meaning a secret flaw in software the maker hasn't patched. It is a convincing email and a person who clicks it.
If you or someone you know receives an unexpected email from a Portuguese government body or business asking you to open an attachment or review a receipt for a transaction you don't remember making, treat it as suspect until you can verify it by calling the organisation directly on a number you find yourself, not one in the email.
One operational takeaway: an email that arrives with urgency, familiar branding, and an attachment you weren't expecting is the attack. That combination, not any single element alone, is what Lampion depends on.



