# Ousaban Banking Trojan Targets Spanish and Portuguese Banks with Sophisticated Phishing and Steganography Campaign


A Brazilian-origin banking trojan called Ousaban is actively targeting Windows users in Spain and Portugal through a carefully orchestrated phishing campaign that combines fake PDFs, geo-blocking, and sophisticated payload hiding techniques. Security researchers at Fortinet's FortiGuard Labs identified and detailed the campaign in May 2026, revealing an attack chain designed to harvest banking credentials and enable account takeover at financial institutions across the Iberian Peninsula.


## The Threat


Ousaban represents a significant threat to banking customers across Spain and Portugal. The malware operates as a sophisticated credential stealer and session hijacker capable of:


  • Capturing sensitive data: Screenshots and keystroke logging of banking sessions
  • Intercepting account access: Clipboard tampering to modify payment instructions
  • Impersonating legitimate services: Displaying fake authentication prompts and messages
  • Enabling remote control: Granting attackers direct interactive access to compromised systems

  • The trojan actively monitors for banking activity across more than two dozen financial institutions, including:


    | Bank Name | Country |

    |-----------|---------|

    | Banco Santander | Spain |

    | BBVA | Spain |

    | CaixaBank | Spain |

    | Bankinter | Spain |

    | Caixa Geral de Depósitos | Portugal |


    Once installed, Ousaban persists silently on an infected Windows PC, waiting for the victim to access their bank's website. The moment a monitored banking site loads, the malware can take screenshots, capture keystrokes, and inject fake messages into the user's browser—giving attackers the tools necessary to intercept live banking sessions and fraudulently transfer funds.


    ## Background and Context


    Ousaban, also tracked under the alias Javali, belongs to a notorious family of Brazilian banking trojans that security researchers have studied for years. Kaspersky Labs classified Ousaban as part of the "Tetrade"—a group of four related Brazilian banking families:


    1. Ousaban (Javali)

    2. Grandoreiro

    3. Guildma

    4. Melcoz


    These families emerged in Brazil but have since expanded their targeting to Spanish and Portuguese banks. They share code and techniques, borrowing malware components and operational tactics from one another. Ousaban's custom string encryption, for instance, is identical to schemes used by Casbaneiro, another banking trojan in the same ecosystem.


    The expansion into Iberian markets signals a strategic shift by Brazilian cybercriminals to target countries where Portuguese-speaking communities and financial infrastructure create exploitation opportunities. Spain and Portugal also represent significant banking markets, making them attractive targets for account takeover operations.


    Grandoreiro, the most well-known member of the Tetrade, demonstrates the durability of this threat. Despite surviving an Interpol-coordinated takedown in January 2024, Grandoreiro returned to operations within months and continues to target Portuguese banks actively. Its persistent threat underscores the challenge of disrupting Brazilian banking trojan campaigns through law enforcement action alone.


    ## Technical Details


    ### The Attack Chain


    The Ousaban campaign operates through a carefully engineered multi-stage infection process designed to evade detection and ensure that only geographically relevant targets receive the malware payload.


    Stage 1: The Phishing PDF


    The attack begins with a phishing PDF disguised as a corrupted or damaged file. The PDF displays a prompt in Portuguese, asking the victim to press an "Atualizar" (Update) button. When clicked, this button directs the user to a malicious webpage. Alternatively, hidden JavaScript embedded within the PDF can automatically trigger the same redirection without user interaction—a technique that increases infection success rates.


    Stage 2: Geo-Blocking and Screening


    Once the victim lands on the malicious webpage, which poses as a tax-document and software installer portal, Fortinet's researchers observed a screening mechanism designed to prevent security researchers and out-of-scope targets from downloading the malware.


    In earlier versions of the campaign, the screening occurred in the browser itself. The malware operators checked:

  • Visitor IP geolocation to confirm Spain or Portugal
  • Browser language settings
  • Time zone information
  • VPN usage (blocking connections through VPN services)
  • Automated security tool signatures (checking screen resolution, installed fonts, and other system characteristics)

  • In the current version, Ousaban operators have shifted the screening logic to their backend server, obscuring the exact filtering rules and making it harder for security researchers to understand the targeting criteria. Visitors from outside Spain and Portugal receive a Spanish-language "access denied" message, preventing out-of-region analysis and slowing threat research.


    Stage 3: Steganographic Payload Delivery


    Visitors who pass the geo-blocking check receive what appears to be a PDF file, but is actually a steganographic image—a technique that hides a ZIP file inside the visual data of an image file. To the user, it appears as a simple PDF icon, but the image file contains the compressed Ousaban payload.


    The malware's installer script:

    1. Downloads the image file

    2. Extracts the hidden ZIP archive

    3. Unpacks the Ousaban trojan executable

    4. Executes the malware

    5. Deletes the image, ZIP file, and installer script to minimize forensic evidence


    Stage 4: Persistence


    Once executing, Ousaban establishes persistence by adding a Windows registry entry named "Financeiro" (Portuguese for "finance"), ensuring the malware restarts automatically when Windows boots.


    ### Command and Control Infrastructure


    Ousaban's command and control infrastructure employs deliberate obfuscation to prevent disruption:


  • Decoy indicators: The malware carries a Pastebin link pointing to a server address, but Fortinet confirmed this address is a red herring, not the true command server
  • Dynamic domain generation: The malware reads the current date from a Google-hosted page, combines it with a fixed secret value, and constructs a domain address that changes daily
  • Previous infrastructure hiding: Earlier Ousaban campaigns hid configuration data in Google Docs, another approach that exploits legitimate services to avoid network-level blocking

  • This dynamic command-and-control approach means that blocking yesterday's command server has minimal impact—the malware simply uses today's derived address tomorrow, making it exceptionally difficult for network defenders to maintain effective block lists.


    ## Implications


    ### Risk to Financial Institutions and Customers


    The Ousaban campaign poses a direct threat to account security at Spanish and Portuguese banks. The malware's ability to capture screenshots, intercept keystrokes, and display fake authentication prompts means that even customers using strong passwords remain vulnerable to account takeover.


    ### Broader Trend: Brazilian Banking Trojan Persistence


    The Ousaban campaign reinforces a critical pattern: Brazilian banking trojans are resilient, adaptive, and operationally mature. Despite Interpol's 2024 action against Grandoreiro, the threat ecosystem has not weakened—it has instead fragmented and dispersed across multiple families that share code and techniques.


    ### Implications for Defenders


    The geographic targeting and sophisticated screening mechanisms suggest that Ousaban operators are:

  • Operating with operational security discipline
  • Willing to invest in infrastructure to avoid automated analysis
  • Focused on maximizing success rates by filtering out low-value targets (researchers, out-of-region users, automated systems)

  • This indicates a professional, organized criminal operation rather than opportunistic malware distribution.


    ## Recommendations


    ### For Banking Customers


  • Treat suspicious PDF prompts as hostile: Any PDF claiming a file is corrupted and requesting you to press "Update," "Atualizar," or similar buttons should be treated as a phishing attempt, even if it appears to come from a bank
  • Avoid clicking links in unexpected emails or PDFs: Navigate directly to your bank's official website by typing the URL in your browser
  • Be suspicious of "ClickFix" scams: Do not paste commands into your terminal or command prompt, even if told you are "fixing an error"
  • Monitor account activity: Regularly review your bank statements and transaction history for unauthorized activity
  • Enable multi-factor authentication: Where available, use authenticators or hardware security keys rather than SMS-based 2FA

  • ### For Financial Institutions


  • Implement enhanced monitoring: Deploy behavioral analytics to detect unusual account access patterns, especially geographically anomalous logins or atypical transaction patterns
  • Security awareness training: Conduct regular phishing and malware education for customers, with specific warnings about PDF-based lures
  • Endpoint detection and response (EDR): Recommend or mandate EDR solutions for corporate clients, with particular attention to registry persistence mechanisms
  • API security: Harden internal APIs and transaction systems to prevent lateral movement if a customer's endpoint is compromised
  • Threat intelligence integration: Subscribe to threat feeds specific to Brazilian banking trojans and Iberian targeting campaigns

  • ### For IT Security Teams


  • Registry monitoring: Deploy YARA rules and detection signatures for registry entries containing Portuguese-language financial terms (e.g., "Financeiro")
  • Steganography detection: Implement file scanning tools capable of detecting steganographically-encoded payloads hidden within image files
  • Command-and-control intelligence: Maintain dynamic block lists for domain generation algorithms, updating daily if possible
  • Phishing infrastructure takedowns: Coordinate with hosting providers and domain registrars to remove malicious landing pages

  • ---


    ## HackWire Analysis


    The Ousaban campaign exemplifies why Brazilian banking trojans remain one of the most persistent threats to financial institutions globally. What distinguishes Ousaban from typical malware is not technical sophistication alone—it's operational maturity. The operators conduct geolocation screening, invest in dynamic command infrastructure, and deliberately obfuscate their true C2 addresses. These are not beginner tactics.


    The deeper concern is the ecosystem pattern: Ousaban exists within a network of related families (Grandoreiro, Guildma, Melcoz) that share code, learn from each other, and adapt rapidly to defensive measures. Interpol's 2024 takedown of Grandoreiro had measurable short-term impact, yet the family returned within months. This suggests that dismantling individual malware families through law enforcement is insufficient—the underlying criminal infrastructure and operational knowledge persist across the ecosystem.


    The shift from browser-based to server-side screening is particularly telling. By moving geo-filtering to their backend, Ousaban operators have made it harder for researchers to reverse-engineer the campaign's rules and scope. This demonstrates that the threat actors are actively studying defensive research and adapting to make analysis more difficult. It's a hallmark of an adversary that learns and improves.


    For banks and security teams, the takeaway is clear: geo-blocking alone is not a complete defense. Ousaban's success depends on users clicking malicious PDFs. The weakest link remains human attention. Aggressive customer education about PDF-based lures, paired with behavioral analytics that catch account takeovers in progress, remains the best practical defense.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)