Remove 02
Remove 2020 Remove Article Remove Government Remove IT
article thumbnail

The hidden C2: Lampion trojan release 212 is on the rise and using a C2 server for two years

Security Affairs

This piece of malware is known for the usage of the Portuguese Government Finance & Tax (Autoridade Tributária e Aduaneira) email templates to lure victims to install the malicious loader (a VBS file). Filename : Comprovativo de pagamento_2866-XRNM_15-02-2022 06-43-54_28.vbs FUD capabilities of the Lampions’ VBS loader.