Threat reportMalwareTL-2026-1046

Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked Tetrade Campaign to Target Iberian Banking Users in Spain and Portugal

highACTIVE

Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked (TL-2026-1046), also tracked as Javali, is a high-severity malware campaign, first published 2026-07-01. It is attributed to Tetrade (Brazil) with medium confidence, affects Microsoft Windows, maps to 30 MITRE ATT&CK techniques (T1005, T1027, T1027.003), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
30MITRE ATT&CK
Actors
2Tetrade
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-1046

Threat ID
TL-2026-1046
Also known as
Javali, Ousaban/Javali Iberian Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Tetrade, Javali operators
Attribution confidence
MEDIUM
Nation-state nexus
Brazil
Motivation
FINANCIAL
Target sectors
finance, banking
Target regions
spain, portugal, Iberian Peninsula, Europe, brazil, Latin America
Detection rules
9
Indicators of compromise
21

Malware and tooling in Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked

Malware and tooling: Astaroth, Grandoreiro - S0531, Javali - S0528, Melcoz - S0530, Metamorfo, Ousaban

How Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked works

FortiGuard Labs identified an active campaign delivering the Ousaban (Javali) banking trojan against banking users in Spain and Portugal, a geographic expansion beyond its traditional Brazilian/LATAM targeting. The campaign uses a steganography-laden phishing PDF, ClickFix-style social engineering, and heavy anti-analysis/geofencing to deploy a trojan capable of keylogging, screenshot capture, clipboard tampering, and remote-controlled live session hijacking against at least 20 banks including Banco Santander, BBVA, CaixaBank, Bankinter, and Caixa Geral de Depositos.

Ousaban, also tracked as Javali, is a Delphi-based Brazilian banking trojan first documented between 2017 and 2018 as part of the 'Tetrade' cluster of LATAM banking malware families identified by Kaspersky (alongside Guildma/Astaroth, Melcoz, and Grandoreiro). Historically confined to Brazil and Mexico, Ousaban shares custom string-encryption routines with the related Casbaneiro family and has repeatedly abused legitimate cloud services -- Amazon S3 and Microsoft Azure for second-stage payload hosting, and Google Docs and YouTube for command-and-control (C2) configuration retrieval -- a tradecraft pattern common across the Tetrade families.

In the campaign identified by FortiGuard Labs in May 2026 and reported by The Hacker News on 2026-07-01, Ousaban operators pivoted the family's targeting from Brazil to the Iberian Peninsula, geofencing infections to victims in Spain and Portugal and targeting at least 20 regional banks. The infection chain begins with a phishing PDF disguised as a corrupted document containing an 'Atualizar' (Update) button; interacting with it triggers hidden JavaScript that autonomously opens a malicious webpage masquerading as a tax-document or installer portal, a ClickFix-style social-engineering pattern. The delivery infrastructure performs server-side victim screening -- checking IP address, browser language, timezone, screen size, font enumeration, and VPN usage -- before serving the payload; non-qualifying visitors receive a Spanish-language 'access denied' page, and current-version screening logic is server-side, obscuring detection rules from researchers.

Qualifying victims receive a payload that uses steganography: the actual executable is hidden inside an image file that is presented with a PDF icon. A script extracts the embedded executable, executes it, and deletes forensic artifacts. Ousaban establishes persistence via a 'Financeiro' Windows Run registry key and stages components under paths such as C:\SysMain_5874288. Command-and-control is deliberately obfuscated: a Pastebin link resolves to a decoy server address, with the true C2 address rotated daily using a formula combining the current date and a fixed secret -- consistent with the Tetrade families' history of abusing web services (Google Docs, YouTube, Pastebin) as C2 dead-drop resolvers rather than static IP/domain infrastructure.

Once resident, Ousaban waits for the victim to visit a targeted bank's website, then activates capabilities including keystroke logging, periodic screenshot capture, clipboard tampering/replacement, injection of fake overlay messages, and full remote-access/remote-control functionality enabling operators to hijack the victim's live authenticated banking session -- an account-takeover technique that bypasses many transaction-based anti-fraud and MFA controls because it rides the victim's own authenticated session rather than stealing static credentials.

The campaign is best understood in the context of the broader Tetrade cluster's 2024-2026 resurgence: Grandoreiro, historically distributed via nearly identical MSI/DGA tradecraft and also historically targeting Spain and Portugal, was disrupted by an INTERPOL-coordinated takedown in January 2024 but resurged within months (May 2024). Ousaban's Iberian expansion in 2026 mirrors this pattern of LATAM banking-trojan operators diversifying beyond Brazil toward Spanish/Portuguese-speaking markets in Europe where Spanish and Portuguese banks maintain large retail customer bases, leveraging language and cultural overlap to reuse lure content and mule/money-laundering networks.

MITRE ATT&CK techniques used in TL-2026-1046

Collection

T1005 Data from Local System; T1056.001 Keylogging; T1113 Screen Capture; T1115 Clipboard Data

Defense Evasion

T1027 Obfuscated Files or Information; T1027.003 Steganography; T1036 Masquerading; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518.001 Security Software Discovery; T1614 System Location Discovery

Execution

T1059.007 JavaScript; T1204.001 Malicious Link; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1219 Remote Access Tools; T1573 Encrypted Channel

Impact

T1531 Account Access Removal

Persistence

T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1566.001 Spearphishing Attachment

Resource Development

T1583.001 Domains; T1584.006 Web Services; T1587.001 Malware

Reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked

  • Microsoft — Windows
    Vulnerable versions: all supported Windows desktop versions
  • Multiple — Online banking portals (Banco Santander, BBVA, CaixaBank, Bankinter, Caixa Geral de Depositos, and 15+ other Iberian banks)
    Vulnerable versions: N/A - client-side credential/session theft, not a banking-platform vulnerability

Remediation for Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked

Immediate actions

  • Block execution of unsigned/unexpected executables extracted from image or PDF attachments via application control (AppLocker/WDAC)
  • Alert on and block creation of the 'Financeiro' Run registry key and unexpected entries under HKCU/HKLM ...\Run
  • Block or heavily monitor outbound requests to Pastebin, generic file-hosting, and Google Docs/YouTube URLs from endpoint processes not associated with browsers
  • Deploy FortiMail/secure email gateway rules to flag PDFs containing 'corrupted file' lures with embedded JavaScript auto-navigation
  • Enforce banking-session step-up authentication (out-of-band transaction signing) resistant to live session/overlay hijacking

Workarounds

  • Disable JavaScript execution in PDF readers (e.g., Adobe Acrobat 'Enable JavaScript' setting) to break the autonomous-webpage-opening trigger

Longer-term hardening

  • Deploy EDR with behavioral detection for steganographic payload extraction (image-to-PE unpacking) and process injection into browser processes
  • Implement DNS/web filtering with geofencing-aware threat intel to catch server-side victim-screening infrastructure reuse
  • User awareness training on 'corrupted file / click to update' PDF phishing lures and ClickFix-style social engineering
  • Share IOCs and TTPs with regional banking-sector ISACs (Spain/Portugal) given active multi-bank targeting

Timeline of Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked

  • Ousaban (Javali) banking trojan first emerges as part of Kaspersky's 'Tetrade' cluster of Brazilian banking malware families, initially targeting Brazil and Mexico
  • Kaspersky Securelist publishes 'The Tetrade: Brazilian banking malware goes global,' documenting Ousaban/Javali alongside Guildma, Melcoz, and Grandoreiro expanding beyond Brazil
  • ESET Research publishes 'Ousaban: Private photo collection hidden in a CABinet,' documenting the family's steganographic payload-concealment technique
  • Independent researcher publishes technical analysis of Ousaban's MSI installer delivery mechanism
  • Netskope publishes 'Ousaban: LATAM Banking Malware Abusing Cloud Services,' documenting abuse of Amazon S3, Microsoft Azure, and Google Docs for payload hosting and C2 configuration
  • INTERPOL-coordinated law enforcement operation disrupts Grandoreiro, a related Tetrade family with a similar Spain/Portugal targeting history
  • Grandoreiro operations resurge within months of the takedown, signaling continued Tetrade-cluster resilience
  • Fortinet observes prior-generation Ousaban campaign infrastructure using alternative initial-access entry points, later superseded by the PDF/steganography chain
  • FortiGuard Labs identifies the ongoing Ousaban campaign geofenced to Spain and Portugal, targeting at least 20 regional banks
  • The Hacker News publishes public reporting on the FortiGuard Labs findings, disclosing the campaign's phishing-PDF, steganography, and ClickFix-style delivery chain

Sources cited for Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked

Detection coverage for TL-2026-1046

As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1046 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats