← BACK TO FEED
banking trojanphishingOusabansteganographymalware

Ousaban Banking Trojan Is Hunting Iberian Bank Customers via Fake PDF Lures

Ousaban, a Brazilian banking trojan also known as Javali, is targeting Windows users in Spain and Portugal through phishing PDFs that trick victims into downloading malware hidden inside an image file using steganography. Once installed, it monitors banking activity, capturing keystrokes and screenshots, and gives attackers remote control to hijack live banking sessions at over two dozen Iberian banks. The campaign uses geofencing to restrict delivery to genuine targets in the two countries, and evades detection through a rotating daily command server address and a custom encryption scheme that has proved resilient for years.

A Brazilian banking trojan called Ousaban is running a focused campaign against Windows users banking in Spain and Portugal. Fortinet's FortiGuard Labs spotted the operation in May 2026, and it's nastier than it looks at first glance.

The attack chain starts with a phishing PDF dressed up as a corrupted file. Victims are prompted to hit an 'Atualizar' (Update) button, which loads a malicious webpage. There's also hidden JavaScript in the PDF that can trigger the same redirect automatically, so even a cautious click isn't necessarily safe.

The landing page poses as a tax-document or software installer portal, but before anything happens, the campaign screens its visitors carefully. Earlier variants ran these checks client-side, inspecting the visitor's IP, language settings, and time zone, while filtering out VPN traffic and security sandboxes by checking things like screen resolution and installed fonts. The current version has moved all of that logic server-side, which means the exact rules are now hidden from researchers. Either way, if you're not in Spain or Portugal, you just get a Spanish-language 'access denied' message and nothing else.

Pass the check and the malware delivery begins. A script downloads what appears to be a PDF icon but is actually a ZIP file embedded inside an image using steganography. Ousaban gets unpacked from that ZIP, executed, and the image, ZIP, and script are then deleted to reduce forensic traces. The trojan establishes persistence via a Windows registry Run key called 'Financeiro', Portuguese for finance.

Once resident, Ousaban sits silently until the victim opens one of more than two dozen targeted banking sites across the two countries, including Banco Santander, BBVA, CaixaBank, Bankinter, and Caixa Geral de Depósitos. At that point it can capture keystrokes and screenshots, manipulate the clipboard, throw up fake overlays, and hand the attacker remote control. That's everything needed to hijack a live banking session.

Tracking the command server is deliberately difficult. The malware carries a Pastebin link pointing to what Fortinet says is a decoy address. The real command server rotates daily. Ousaban reads the current date from a Google page, combines it with a hardcoded secret to construct a URL, and uses that to find its actual controller. Blocking yesterday's address accomplishes nothing. Stashing configuration details inside legitimate web services is a long-standing Ousaban habit; earlier campaigns used Google Docs for the same purpose.

Ousaban, also tracked as Javali, is one of the so-called Tetrade group of Brazilian banking trojans catalogued by Kaspersky, alongside Grandoreiro, Guildma, and Melcoz. These families developed in Brazil and gradually expanded into Spain and Portugal, sharing code along the way. Ousaban's string encryption is the same custom scheme found in Casbaneiro, a related family.

Grandoreiro is the most well-known of the group and illustrates just how persistent this threat landscape is. It survived an Interpol-coordinated takedown in January 2024 and was operational again within months. A campaign targeting Portuguese banks was reported this year. Fortinet has linked the same infrastructure to Ousaban activity in late 2025 that used other delivery methods, including 'ClickFix', a technique that tricks victims into pasting a malicious command themselves under the pretence of fixing a technical error.

For defenders, the lure is the most obvious intervention point. Any PDF claiming to be corrupted and asking you to press Update should be treated as hostile, full stop. The same goes for anything instructing users to paste a command to fix an error. Unexpected invoice, factura, or tax-document attachments are also suspect, particularly in Spain and Portugal.

It's worth noting that because the victim screening now happens server-side, an automated sandbox that simply fetches the URL may receive only the Spanish error page rather than the payload. Gateway detonation alone can miss this one.

Fortinet's report includes domains, IP addresses, and file hashes to block. Defenders should monitor for the Financeiro registry Run key and files dropped to C:\SysMain_5874288. FortiGuard antivirus detects the samples, and FortiMail flags the phishing email.

The trojan itself is not new. What is relatively new is the delivery wrapper around it: tight geofencing, steganographic payload hiding, and a rotating daily command address. The whole setup is designed to ensure the malware is visible only to genuine victims in two countries, and to almost nobody else.

READ NEXT
Brazilian Gov Websites Hijacked to Deliver Malware in Active Banking CampaignOkoBot Malware Serves Fake Recovery Pages Inside Real Ledger and Trezor AppsVEIL#DROP: How Attackers Are Hiding Malware Inside Google's Blogger