Infosecurity-Magazine Ousaban Banking Trojan Targets Users in Spain and Portugal with Advanced Techniques
Article Content
- •Ousaban targets banking users in Spain and Portugal using sophisticated evasion techniques.
- •The malware employs phishing PDFs and steganography to deliver its payload while avoiding detection.
- •It monitors multiple banking institutions and has a dynamic command and control infrastructure.
The Ousaban banking trojan has been identified targeting Windows users in Spain and Portugal since May 2026. This malware employs phishing PDFs disguised as corrupted files to lure victims into clicking an 'Atualizar' button, leading to a malicious webpage. The campaign uses geofencing to restrict access to users in the targeted countries, blocking those using VPNs or automated tools. Once the victim's environment is verified, the trojan delivers its payload hidden within an image file using steganography. Ousaban monitors over two dozen banks, including Santander and BBVA, capturing screenshots and keystrokes to steal credentials. The command and control infrastructure changes daily, making detection and blocking difficult. Fortinet has flagged the malware and its phishing emails, but the campaign remains active.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Grandoreiro and BBVA in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…