# Ousaban Banking Trojan Targets Spanish and Portuguese Banks with Sophisticated Phishing and Steganography Campaign
A Brazilian-origin banking trojan called Ousaban is actively targeting Windows users in Spain and Portugal through a carefully orchestrated phishing campaign that combines fake PDFs, geo-blocking, and sophisticated payload hiding techniques. Security researchers at Fortinet's FortiGuard Labs identified and detailed the campaign in May 2026, revealing an attack chain designed to harvest banking credentials and enable account takeover at financial institutions across the Iberian Peninsula.
## The Threat
Ousaban represents a significant threat to banking customers across Spain and Portugal. The malware operates as a sophisticated credential stealer and session hijacker capable of:
The trojan actively monitors for banking activity across more than two dozen financial institutions, including:
| Bank Name | Country |
|-----------|---------|
| Banco Santander | Spain |
| BBVA | Spain |
| CaixaBank | Spain |
| Bankinter | Spain |
| Caixa Geral de Depósitos | Portugal |
Once installed, Ousaban persists silently on an infected Windows PC, waiting for the victim to access their bank's website. The moment a monitored banking site loads, the malware can take screenshots, capture keystrokes, and inject fake messages into the user's browser—giving attackers the tools necessary to intercept live banking sessions and fraudulently transfer funds.
## Background and Context
Ousaban, also tracked under the alias Javali, belongs to a notorious family of Brazilian banking trojans that security researchers have studied for years. Kaspersky Labs classified Ousaban as part of the "Tetrade"—a group of four related Brazilian banking families:
1. Ousaban (Javali)
2. Grandoreiro
3. Guildma
4. Melcoz
These families emerged in Brazil but have since expanded their targeting to Spanish and Portuguese banks. They share code and techniques, borrowing malware components and operational tactics from one another. Ousaban's custom string encryption, for instance, is identical to schemes used by Casbaneiro, another banking trojan in the same ecosystem.
The expansion into Iberian markets signals a strategic shift by Brazilian cybercriminals to target countries where Portuguese-speaking communities and financial infrastructure create exploitation opportunities. Spain and Portugal also represent significant banking markets, making them attractive targets for account takeover operations.
Grandoreiro, the most well-known member of the Tetrade, demonstrates the durability of this threat. Despite surviving an Interpol-coordinated takedown in January 2024, Grandoreiro returned to operations within months and continues to target Portuguese banks actively. Its persistent threat underscores the challenge of disrupting Brazilian banking trojan campaigns through law enforcement action alone.
## Technical Details
### The Attack Chain
The Ousaban campaign operates through a carefully engineered multi-stage infection process designed to evade detection and ensure that only geographically relevant targets receive the malware payload.
Stage 1: The Phishing PDF
The attack begins with a phishing PDF disguised as a corrupted or damaged file. The PDF displays a prompt in Portuguese, asking the victim to press an "Atualizar" (Update) button. When clicked, this button directs the user to a malicious webpage. Alternatively, hidden JavaScript embedded within the PDF can automatically trigger the same redirection without user interaction—a technique that increases infection success rates.
Stage 2: Geo-Blocking and Screening
Once the victim lands on the malicious webpage, which poses as a tax-document and software installer portal, Fortinet's researchers observed a screening mechanism designed to prevent security researchers and out-of-scope targets from downloading the malware.
In earlier versions of the campaign, the screening occurred in the browser itself. The malware operators checked:
In the current version, Ousaban operators have shifted the screening logic to their backend server, obscuring the exact filtering rules and making it harder for security researchers to understand the targeting criteria. Visitors from outside Spain and Portugal receive a Spanish-language "access denied" message, preventing out-of-region analysis and slowing threat research.
Stage 3: Steganographic Payload Delivery
Visitors who pass the geo-blocking check receive what appears to be a PDF file, but is actually a steganographic image—a technique that hides a ZIP file inside the visual data of an image file. To the user, it appears as a simple PDF icon, but the image file contains the compressed Ousaban payload.
The malware's installer script:
1. Downloads the image file
2. Extracts the hidden ZIP archive
3. Unpacks the Ousaban trojan executable
4. Executes the malware
5. Deletes the image, ZIP file, and installer script to minimize forensic evidence
Stage 4: Persistence
Once executing, Ousaban establishes persistence by adding a Windows registry entry named "Financeiro" (Portuguese for "finance"), ensuring the malware restarts automatically when Windows boots.
### Command and Control Infrastructure
Ousaban's command and control infrastructure employs deliberate obfuscation to prevent disruption:
This dynamic command-and-control approach means that blocking yesterday's command server has minimal impact—the malware simply uses today's derived address tomorrow, making it exceptionally difficult for network defenders to maintain effective block lists.
## Implications
### Risk to Financial Institutions and Customers
The Ousaban campaign poses a direct threat to account security at Spanish and Portuguese banks. The malware's ability to capture screenshots, intercept keystrokes, and display fake authentication prompts means that even customers using strong passwords remain vulnerable to account takeover.
### Broader Trend: Brazilian Banking Trojan Persistence
The Ousaban campaign reinforces a critical pattern: Brazilian banking trojans are resilient, adaptive, and operationally mature. Despite Interpol's 2024 action against Grandoreiro, the threat ecosystem has not weakened—it has instead fragmented and dispersed across multiple families that share code and techniques.
### Implications for Defenders
The geographic targeting and sophisticated screening mechanisms suggest that Ousaban operators are:
This indicates a professional, organized criminal operation rather than opportunistic malware distribution.
## Recommendations
### For Banking Customers
### For Financial Institutions
### For IT Security Teams
---
## HackWire Analysis
The Ousaban campaign exemplifies why Brazilian banking trojans remain one of the most persistent threats to financial institutions globally. What distinguishes Ousaban from typical malware is not technical sophistication alone—it's operational maturity. The operators conduct geolocation screening, invest in dynamic command infrastructure, and deliberately obfuscate their true C2 addresses. These are not beginner tactics.
The deeper concern is the ecosystem pattern: Ousaban exists within a network of related families (Grandoreiro, Guildma, Melcoz) that share code, learn from each other, and adapt rapidly to defensive measures. Interpol's 2024 takedown of Grandoreiro had measurable short-term impact, yet the family returned within months. This suggests that dismantling individual malware families through law enforcement is insufficient—the underlying criminal infrastructure and operational knowledge persist across the ecosystem.
The shift from browser-based to server-side screening is particularly telling. By moving geo-filtering to their backend, Ousaban operators have made it harder for researchers to reverse-engineer the campaign's rules and scope. This demonstrates that the threat actors are actively studying defensive research and adapting to make analysis more difficult. It's a hallmark of an adversary that learns and improves.
For banks and security teams, the takeaway is clear: geo-blocking alone is not a complete defense. Ousaban's success depends on users clicking malicious PDFs. The weakest link remains human attention. Aggressive customer education about PDF-based lures, paired with behavioral analytics that catch account takeovers in progress, remains the best practical defense.
— *HackWire Editorial*
---
## Related Coverage