Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails
Hackers are using fake payment receipt emails to deliver a 750MB Lampion remote access trojan to targets in Portugal.
The campaign relies on familiar financial language, convincing business details, and oversized files designed to slow down analysis and evade security checks.
The attack begins with phishing emails that pose as routine financial or administrative messages.
Recipients are urged to open a ZIP attachment that appears to contain a payment receipt, turning an ordinary business task into the first step of a malware infection.
After the second stage of the attack was examined, analysts from Acronis identified the activity as a new Lampion campaign focused heavily on Portuguese users.
The researchers found that 94.6 percent of detections were in Portugal, showing that the operators continue to tailor their lures, language, and branding to a specific audience.
Lampion is a Brazilian banking malware family first documented in 2019 and linked to the ChePro lineage.
Although it originated in Brazil, its operators have repeatedly targeted Portuguese-speaking victims, using localized scams to make malicious messages look more credible.

The latest activity shows how older banking malware can remain effective when attackers improve the delivery process.
Instead of placing everything in one file, the operators spread the infection across several stages, making it harder for users and security teams to see the full attack chain.
Acronis said in a report shared with Cyber Security News (CSN) that the campaign uses ZIP archives, padded HTML files, JavaScript, and several Visual Basic Script stages before deploying the final payload.
This approach resembles the evolving tactics covered in Lampion ClickFix attack campaign, where attackers also used social engineering and layered scripts to avoid detection.
Hackers Hide 750MB Lampion RAT
The phishing message uses a payment receipt as its central lure because the subject is familiar and urgent.
It includes credibility markers such as confidentiality notices, automated mailbox text, business addresses, and social media references to make the email blend into normal corporate communication.
One observed ZIP attachment was named COMPROVATIVO-JUNHO_OJLWnObxFOyTZkx_01-06-2026_104.zip.
Inside was a roughly 1.3MB HTML document padded with meaningless code and random strings, a tactic intended to make the file harder to inspect and less likely to match common detection signatures.

When opened, the HTML file displays a fake SAPO Transfer page that imitates a trusted Portuguese online service.
The visual trick is meant to reassure victims while hidden JavaScript retrieves the next malware stage in the background.

The downloaded JavaScript is inserted into the page and executed without obvious warning signs.
This layered process shows why organizations should treat unexpected attachments carefully, especially messages that create pressure around invoices, receipts, and financial confirmations.
The operators then deploy VBS files with names that continue the payment-document theme, including Comprovativo_Junho_15-06-2026-WjGAxGL.vbs.
Related threats have used similar attachment-based deception, as reported in coverage of common phishing attack vectors, where malicious files remain a common route into corporate networks.
These VBS scripts are also padded with junk data. One analyzed file was about 7MB, despite containing only around 22KB of useful code, demonstrating how file size inflation can conceal malicious behavior while complicating automated and manual review.
750MB RAT Payload
The final VBS component performs victim checks, gathers system information, and contacts command-and-control infrastructure for the next payload. It can create scheduled tasks, remove competing VBS files from the temporary folder, and generate a unique identifier from system details.
The malware downloads a DLL into a timestamp-named folder under the user’s AppData directory. It uses HTTP range requests to retrieve the file in 10MB pieces, then rebuilds it locally before scheduling execution through rundll32.
Figure 7: Download of RAT component
The final DLL is around 750MB, but its size does not reflect genuine complexity. Researchers attribute much of it to junk padding, a long-used Lampion tactic that makes the payload harder to scan, transfer, and analyze.
Once launched, the DLL uses an exported function named jangadeiro and acts as the primary remote access trojan.
It can give attackers access to the compromised system and support data theft, creating risk for both individuals and organizations.
This campaign also fits a wider pattern of malware targeting European banking users through localized lures. Recent reporting on Ousaban phishing PDF attacks shows that attackers are still combining fake financial documents with scripts and staged payloads to reach victims in Portugal and Spain.
Defenders should investigate unusually large DLL files in AppData, especially those stored in timestamp-named directories.
They should also review scheduled tasks that use cmd /c move, rundll32, or VBS files in temporary folders, and inspect suspicious outbound connections linked to payment-themed attachments.
Teams should verify unexpected receipts with the sender through a separate trusted channel before opening them.
Using attachment scanning and sandboxing can help, but analysts should remember that geofencing and victim checks may prevent a malicious file from showing its full behavior during a single test, as discussed in guidance on email virus sandbox checks.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 87efeada5fe39a94cefc6151fd84af223d0e0e2b070daec606274481ed87b87b |
Phishing email hash |
| SHA-256 | ab46f7c4d3f717bb1e61d2f236917976d2a85be6958ae099fee79ea6e9031e37b |
ZIP attachment hash |
| SHA-256 | 1c101bd1ba134ffbea61f9fac2b7c8fbd13ca113a37944abdc131ef86da92acc |
HTML file hash |
| SHA-256 | 6618bb692fb3f5d7959f8db1fedaaac5e8a36fb901397a008aa2b88874448fd |
Second-stage VBS hash |
| SHA-256 | 036c8f32012abdcb9a389ae9c284da89505e830bca74eb1aa9ea3794b067aab |
Final-stage VBS hash |
| File name | COMPROVATIVO-JUNHO_OJLWnObxFOyTZkx_01-06-2026_104.zip |
Malicious ZIP attachment |
| File name | Comprovativo_Junho_15-06-2026-WjGAxGL.vbs |
Observed second-stage VBS file |
| File name | Comprovativo_Maio_18-05-2026-pXiaBxQ.vbs |
Observed second-stage VBS file |
| Domain | auto-contabilistica.com |
Involved domain |
| Domain | autoridade-contabilistica.org |
Involved domain |
| Domain | autoridade-financeira.com |
Involved domain |
| Domain | fat-contabislitaca.com |
Next-stage downloader domain |
| URL | hxxps://fat-contabislitaca[.]com/js/1898.php |
JavaScript downloader URL |
| C2 URL | hxxp://18.218.184[.]201/03_metal7342/trapezio.php |
Final-stage VBS C2 |
| C2 URL | hxxp://18.222.100[.]142/17_moldura8210/regerem.php |
Final-stage VBS C2 |
| C2 URL | hxxp://18.222.100[.]142/18_prateleira1967/revigore.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.135.194[.]95/09_nsabdo/receado.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.139.85[.]102/17_eudhfj/regerem.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.139.85[.]102/18_vdsyuh/revigore.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.139.85[.]102/20_fjegydk/destravares.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.141.199[.]105/13_ytdshe/reimpresso.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.141.199[.]105/15_rjhsymc/unificador.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.141.199[.]105/16_kdsgyue/raquete.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.144.37[.]134/01_sdneow/fruais.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.144.37[.]134/02_sjdhie/reestruturado.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.144.37[.]134/03_osneops/trapezio.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.148.240[.]228/05_dnwodu/equivaler.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.148.240[.]228/06_sndiwds/galgassem.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.150.134[.]118/05_papel6197/equivaler.php |
Final-stage VBS C2 |
| C2 URL | hxxp://3.150.134[.]118/06_couro8254/galgassem.php |
Final-stage VBS C2 |
| C2 URL | hxxp://52.14.160[.]173/10_algodao9148/reunia.php |
Final-stage VBS C2 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.
The post Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails appeared first on Cyber Security News.
Tushar Subhra Dutta
Go to cyber-security-news