# Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked Tetrade Campaign to Target Iberian Banking Users in Spain and Portugal

> FortiGuard Labs identified an active campaign delivering the Ousaban (Javali) banking trojan against banking users in Spain and Portugal, a geographic expansion beyond its traditional Brazilian/LATAM targeting. The campaign uses a steganography-laden phishing PDF, ClickFix-style social engineering, and heavy anti-analysis/geofencing to deploy a trojan capable of keylogging, screenshot capture, clipboard tampering, and remote-controlled live session hijacking against at least 20 banks including Banco Santander, BBVA, CaixaBank, Bankinter, and Caixa Geral de Depositos.

- **Published:** 2026-07-01T00:00:00Z
- **Last reviewed:** 2026-07-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1046
- **ID:** TL-2026-1046
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Tetrade (Brazil)
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Ousaban, also tracked as Javali, is a Delphi-based Brazilian banking trojan first documented between 2017 and 2018 as part of the 'Tetrade' cluster of LATAM banking malware families identified by Kaspersky (alongside Guildma/Astaroth, Melcoz, and Grandoreiro). Historically confined to Brazil and Mexico, Ousaban shares custom string-encryption routines with the related Casbaneiro family and has repeatedly abused legitimate cloud services -- Amazon S3 and Microsoft Azure for second-stage payload hosting, and Google Docs and YouTube for command-and-control (C2) configuration retrieval -- a tradecraft pattern common across the Tetrade families.

In the campaign identified by FortiGuard Labs in May 2026 and reported by The Hacker News on 2026-07-01, Ousaban operators pivoted the family's targeting from Brazil to the Iberian Peninsula, geofencing infections to victims in Spain and Portugal and targeting at least 20 regional banks. The infection chain begins with a phishing PDF disguised as a corrupted document containing an 'Atualizar' (Update) button; interacting with it triggers hidden JavaScript that autonomously opens a malicious webpage masquerading as a tax-document or installer portal, a ClickFix-style social-engineering pattern. The delivery infrastructure performs server-side victim screening -- checking IP address, browser language, timezone, screen size, font enumeration, and VPN usage -- before serving the payload; non-qualifying visitors receive a Spanish-language 'access denied' page, and current-version screening logic is server-side, obscuring detection rules from researchers.

Qualifying victims receive a payload that uses steganography: the actual executable is hidden inside an image file that is presented with a PDF icon. A script extracts the embedded executable, executes it, and deletes forensic artifacts. Ousaban establishes persistence via a 'Financeiro' Windows Run registry key and stages components under paths such as C:\SysMain_5874288. Command-and-control is deliberately obfuscated: a Pastebin link resolves to a decoy server address, with the true C2 address rotated daily using a formula combining the current date and a fixed secret -- consistent with the Tetrade families' history of abusing web services (Google Docs, YouTube, Pastebin) as C2 dead-drop resolvers rather than static IP/domain infrastructure.

Once resident, Ousaban waits for the victim to visit a targeted bank's website, then activates capabilities including keystroke logging, periodic screenshot capture, clipboard tampering/replacement, injection of fake overlay messages, and full remote-access/remote-control functionality enabling operators to hijack the victim's live authenticated banking session -- an account-takeover technique that bypasses many transaction-based anti-fraud and MFA controls because it rides the victim's own authenticated session rather than stealing static credentials.

The campaign is best understood in the context of the broader Tetrade cluster's 2024-2026 resurgence: Grandoreiro, historically distributed via nearly identical MSI/DGA tradecraft and also historically targeting Spain and Portugal, was disrupted by an INTERPOL-coordinated takedown in January 2024 but resurged within months (May 2024). Ousaban's Iberian expansion in 2026 mirrors this pattern of LATAM banking-trojan operators diversifying beyond Brazil toward Spanish/Portuguese-speaking markets in Europe where Spanish and Portuguese banks maintain large retail customer bases, leveraging language and cultural overlap to reuse lure content and mule/money-laundering networks.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1583.001 Domains
- T1584.006 Web Services
- T1587.001 Malware
- T1566.001 Spearphishing Attachment
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1059.007 JavaScript
- T1547.001 Registry Run Keys / Startup Folder
- T1027 Obfuscated Files or Information
- T1027.003 Steganography
- T1036 Masquerading
- T1497 Virtualization/Sandbox Evasion
- T1140 Deobfuscate/Decode Files or Information
- T1070.004 File Deletion
- T1057 Process Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1518.001 Security Software Discovery
- T1614 System Location Discovery
- T1056.001 Keylogging
- T1115 Clipboard Data
- T1113 Screen Capture
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1102.001 Dead Drop Resolver
- T1219 Remote Access Tools
- T1573 Encrypted Channel
- T1041 Exfiltration Over C2 Channel
- T1531 Account Access Removal

## Sources

- [Ousaban Banking Trojan Targets Iberian Peninsula Banking Users](https://thehackernews.com/2026/07/ousaban-banking-trojan-targets-iberian.html)
- [Ousaban: Private photo collection hidden in a CABinet](https://www.welivesecurity.com/2021/05/05/ousaban-private-photo-collection-hidden-cabinet/)
- [Ousaban: LATAM Banking Malware Abusing Cloud Services](https://www.netskope.com/blog/ousaban-latam-banking-malware-abusing-cloud-services)
- [The Tetrade: Brazilian banking malware goes global](https://securelist.com/the-tetrade-brazilian-banking-malware/97779/)
- [Ousaban (win.ousaban) Malware Family Reference](https://malpedia.caad.fkie.fraunhofer.de/details/win.ousaban)
- [Ousaban MSI Installer Analysis](https://gist.github.com/Shivammalaviya/7b705f790038826b5d8a81b411f9e3c6)
- [W32/Ousaban.DX!tr.spy - Virus Encyclopedia Entry](https://fortiguard.fortinet.com/encyclopedia/virus/10163512)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1046
