Skip to content
Malware

Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails

Hackers are using fake payment receipt emails to deliver a 750MB Lampion remote access trojan to targets in Portugal. The campaign relies on familiar financial language, convincing business details, and oversized files designed to slow down analysis and evade security checks. The attack begins with...

· Jul 24, 2026 · 6 min read · 👁 3 views
Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails

Hackers are using fake payment receipt emails to deliver a 750MB Lampion remote access trojan to targets in Portugal.

The campaign relies on familiar financial language, convincing business details, and oversized files designed to slow down analysis and evade security checks.

The attack begins with phishing emails that pose as routine financial or administrative messages.

Recipients are urged to open a ZIP attachment that appears to contain a payment receipt, turning an ordinary business task into the first step of a malware infection.

After the second stage of the attack was examined, analysts from Acronis identified the activity as a new Lampion campaign focused heavily on Portuguese users.

The researchers found that 94.6 percent of detections were in Portugal, showing that the operators continue to tailor their lures, language, and branding to a specific audience.

Lampion is a Brazilian banking malware family first documented in 2019 and linked to the ChePro lineage.

Although it originated in Brazil, its operators have repeatedly targeted Portuguese-speaking victims, using localized scams to make malicious messages look more credible.

Infection chain overview (Source - Acronis)
Infection chain overview (Source – Acronis)

The latest activity shows how older banking malware can remain effective when attackers improve the delivery process.

Instead of placing everything in one file, the operators spread the infection across several stages, making it harder for users and security teams to see the full attack chain.

Acronis said in a report shared with Cyber Security News (CSN) that the campaign uses ZIP archives, padded HTML files, JavaScript, and several Visual Basic Script stages before deploying the final payload.

This approach resembles the evolving tactics covered in Lampion ClickFix attack campaign, where attackers also used social engineering and layered scripts to avoid detection.

Hackers Hide 750MB Lampion RAT

The phishing message uses a payment receipt as its central lure because the subject is familiar and urgent.

It includes credibility markers such as confidentiality notices, automated mailbox text, business addresses, and social media references to make the email blend into normal corporate communication.

One observed ZIP attachment was named COMPROVATIVO-JUNHO_OJLWnObxFOyTZkx_01-06-2026_104.zip.

Inside was a roughly 1.3MB HTML document padded with meaningless code and random strings, a tactic intended to make the file harder to inspect and less likely to match common detection signatures.

Phishing email (Source - Acronis)
Phishing email (Source – Acronis)

When opened, the HTML file displays a fake SAPO Transfer page that imitates a trusted Portuguese online service.

The visual trick is meant to reassure victims while hidden JavaScript retrieves the next malware stage in the background. 

Fake SAPO file transfer page (Source - Acronis)
Fake SAPO file transfer page (Source – Acronis)

The downloaded JavaScript is inserted into the page and executed without obvious warning signs.

This layered process shows why organizations should treat unexpected attachments carefully, especially messages that create pressure around invoices, receipts, and financial confirmations.

The operators then deploy VBS files with names that continue the payment-document theme, including Comprovativo_Junho_15-06-2026-WjGAxGL.vbs.

Related threats have used similar attachment-based deception, as reported in coverage of common phishing attack vectors, where malicious files remain a common route into corporate networks.

These VBS scripts are also padded with junk data. One analyzed file was about 7MB, despite containing only around 22KB of useful code, demonstrating how file size inflation can conceal malicious behavior while complicating automated and manual review.

750MB RAT Payload

The final VBS component performs victim checks, gathers system information, and contacts command-and-control infrastructure for the next payload. It can create scheduled tasks, remove competing VBS files from the temporary folder, and generate a unique identifier from system details.

The malware downloads a DLL into a timestamp-named folder under the user’s AppData directory. It uses HTTP range requests to retrieve the file in 10MB pieces, then rebuilds it locally before scheduling execution through rundll32.

Figure 7: Download of RAT component

The final DLL is around 750MB, but its size does not reflect genuine complexity. Researchers attribute much of it to junk padding, a long-used Lampion tactic that makes the payload harder to scan, transfer, and analyze.

Once launched, the DLL uses an exported function named jangadeiro and acts as the primary remote access trojan.

It can give attackers access to the compromised system and support data theft, creating risk for both individuals and organizations.

This campaign also fits a wider pattern of malware targeting European banking users through localized lures. Recent reporting on Ousaban phishing PDF attacks shows that attackers are still combining fake financial documents with scripts and staged payloads to reach victims in Portugal and Spain.

Defenders should investigate unusually large DLL files in AppData, especially those stored in timestamp-named directories.

They should also review scheduled tasks that use cmd /c moverundll32, or VBS files in temporary folders, and inspect suspicious outbound connections linked to payment-themed attachments.

Teams should verify unexpected receipts with the sender through a separate trusted channel before opening them.

Using attachment scanning and sandboxing can help, but analysts should remember that geofencing and victim checks may prevent a malicious file from showing its full behavior during a single test, as discussed in guidance on email virus sandbox checks.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
SHA-25687efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87bPhishing email hash
SHA-256ab46f7c4d3f717bb1e61d2f236917976d2a85be6958ae099fee79ea6e9031e37bZIP attachment hash
SHA-2561c101bd1ba134ffbea61f9fac2b7c8fbd13ca113a37944abdc131ef86da92accHTML file hash
SHA-2566618bb692fb3f5d7959f8db1fedaaac5e8a36fb901397a008aa2b88874448fdSecond-stage VBS hash
SHA-256036c8f32012abdcb9a389ae9c284da89505e830bca74eb1aa9ea3794b067aabFinal-stage VBS hash
File nameCOMPROVATIVO-JUNHO_OJLWnObxFOyTZkx_01-06-2026_104.zipMalicious ZIP attachment
File nameComprovativo_Junho_15-06-2026-WjGAxGL.vbsObserved second-stage VBS file
File nameComprovativo_Maio_18-05-2026-pXiaBxQ.vbsObserved second-stage VBS file
Domainauto-contabilistica.comInvolved domain
Domainautoridade-contabilistica.orgInvolved domain
Domainautoridade-financeira.comInvolved domain
Domainfat-contabislitaca.comNext-stage downloader domain
URLhxxps://fat-contabislitaca[.]com/js/1898.phpJavaScript downloader URL
C2 URLhxxp://18.218.184[.]201/03_metal7342/trapezio.phpFinal-stage VBS C2
C2 URLhxxp://18.222.100[.]142/17_moldura8210/regerem.phpFinal-stage VBS C2
C2 URLhxxp://18.222.100[.]142/18_prateleira1967/revigore.phpFinal-stage VBS C2
C2 URLhxxp://3.135.194[.]95/09_nsabdo/receado.phpFinal-stage VBS C2
C2 URLhxxp://3.139.85[.]102/17_eudhfj/regerem.phpFinal-stage VBS C2
C2 URLhxxp://3.139.85[.]102/18_vdsyuh/revigore.phpFinal-stage VBS C2
C2 URLhxxp://3.139.85[.]102/20_fjegydk/destravares.phpFinal-stage VBS C2
C2 URLhxxp://3.141.199[.]105/13_ytdshe/reimpresso.phpFinal-stage VBS C2
C2 URLhxxp://3.141.199[.]105/15_rjhsymc/unificador.phpFinal-stage VBS C2
C2 URLhxxp://3.141.199[.]105/16_kdsgyue/raquete.phpFinal-stage VBS C2
C2 URLhxxp://3.144.37[.]134/01_sdneow/fruais.phpFinal-stage VBS C2
C2 URLhxxp://3.144.37[.]134/02_sjdhie/reestruturado.phpFinal-stage VBS C2
C2 URLhxxp://3.144.37[.]134/03_osneops/trapezio.phpFinal-stage VBS C2
C2 URLhxxp://3.148.240[.]228/05_dnwodu/equivaler.phpFinal-stage VBS C2
C2 URLhxxp://3.148.240[.]228/06_sndiwds/galgassem.phpFinal-stage VBS C2
C2 URLhxxp://3.150.134[.]118/05_papel6197/equivaler.phpFinal-stage VBS C2
C2 URLhxxp://3.150.134[.]118/06_couro8254/galgassem.phpFinal-stage VBS C2
C2 URLhxxp://52.14.160[.]173/10_algodao9148/reunia.phpFinal-stage VBS C2

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you