Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked Tetrade Campaign to Target Iberian Banking Users in Spain and Portugal — Threadlinqs Intelligence
As of 2026-07-01, Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked Tetrade Campaign to Target Iberian Banking Users in Spain and Portugal is a high-severity malware threat attributed to Tetrade (Ousaban (Brazil), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1046 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Tetrade (Ousaban · Brazil · FINANCIAL
FortiGuard Labs identified an active campaign delivering the Ousaban (Javali) banking trojan against banking users in Spain and Portugal, a geographic expansion beyond its traditional Brazilian/LATAM
Ousaban, also tracked as Javali, is a Delphi-based Brazilian banking trojan first documented between 2017 and 2018 as part of the 'Tetrade' cluster of LATAM banking malware families identified by Kaspersky (alongside Guildma/Astaroth, Melcoz, and Grandoreiro). Historically confined to Brazil and Mexico, Ousaban shares custom string-encryption routines with the related Casbaneiro family and has repeatedly abused legitimate cloud services -- Amazon S3 and Microsoft Azure for second-stage payload hosting, and Google Docs and YouTube for command-and-control (C2) configuration retrieval -- a tradecraft pattern common across the Tetrade families.
In the campaign identified by FortiGuard Labs in May 2026 and reported by The Hacker News on 2026-07-01, Ousaban operators pivoted the family's targeting from Brazil to the Iberian Peninsula, geofencing infections to victims in Spain and Portugal and targeting at least 20 regional banks. The infection chain begins with a phishing PDF disguised as a corrupted document containing an 'Atualizar' (Update) button; interacting with it triggers hidden JavaScript that autonomously opens a malicious webpage masquerading as a tax-document or installer portal, a ClickFix-style social-engineering pattern. The delivery infrastructure performs server-side victim screening -- checking IP address, browser language, timezone, screen size, font enumeration, and VPN usage -- before serving the payload; non-qualifying visitors receive a Spanish-language 'access denied' page, and current-version screening logic is server-side, obscuring detection rules from researchers.
Qualifying victims receive a payload that uses steganography: the actual executable is hidden inside an image file that is presented with a PDF icon. A script extracts the embedded executable, executes it, and deletes forensic artifacts. Ousaban establishes persistence via a 'Financeiro' Windows Run registry key and stages components under paths such as C:\SysMain_5874288. Command-and-control is deliberately obfuscated: a Pastebin link resolves to a decoy server address, with the true C2 address rotated daily using a formula combining the current date and a fixed secret -- consistent with the Tetrade families' history of abusing web services (Google Docs, YouTube, Pastebin) as C2 dead-drop resolvers rather than static IP/domain infrastructure.
Once resident, Ousaban waits for the victim to visit a targeted bank's website, then activates capabilities including keystroke logging, periodic screenshot capture, clipboard tampering/replacement, injection of fake overlay messages, and full remote-access/remote-control functionality enabling operators to hijack the victim's live authenticated banking session -- an account-takeover technique that bypasses many transaction-based anti-fraud and MFA controls because it rides the victim's own authenticated session rather than stealing static credentials.
The campaign is best understood in the context of the broader Tetrade cluster's 2024-2026 resurgence: Grandoreiro, historically distributed via nearly identical MSI/DGA tradecraft and also historically targeting Spain and Portugal, was disrupted by an INTERPOL-coordinated takedown in January 2024 but resurged within months (May 2024). Ousaban's Iberian expansion in 2026 mirrors this pattern of LATAM banking-trojan operators diversifying beyond Brazil toward Spanish/Portuguese-speaking markets in Europe where Spanish and Portuguese banks maintain large retail customer bases, leveraging language and cultural overlap to reuse lure content and mule/money-laundering networks.
Target sectors: finance, banking
Target regions: spain, portugal, Iberian Peninsula, Europe, brazil, Latin America
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1589, T1583.001, T1584.006, T1587.001, T1566.001, T1204.001, T1204.002, T1059.007, T1547.001, T1027