Threat reportMalwareTL-2026-1079

Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and Steganographic VBS Downloader

highACTIVE

Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian (TL-2026-1079), also tracked as Javali, is a high-severity malware campaign, first published 2026-07-02 and last reviewed 2026-07-23. It is attributed to Tetrade (Brazil) with medium confidence, affects Microsoft Windows (all supported desktop versions), maps to 37 MITRE ATT&CK techniques (T1001.001, T1005, T1010), and is covered by 9 detection rules and 36 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
37MITRE ATT&CK
Actors
2Tetrade
Detection rules
9SPL · KQL · Sigma
IOCs
36Indicators of compromise

Key facts for TL-2026-1079

Threat ID
TL-2026-1079
Also known as
Javali
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Tetrade, Javali operators
Attribution confidence
MEDIUM
Nation-state nexus
Brazil
Motivation
FINANCIAL
Target sectors
finance, banking
Target regions
spain, portugal, Iberian Peninsula, Europe
Detection rules
9
Indicators of compromise
36
Updates
2026-07-23 · revalidated 1× · latest source

Malware and tooling in Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian

Malware and tooling: Astaroth, Grandoreiro - S0531, Melcoz - S0530, Metamorfo, Ousaban

How Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian works

FortiGuard Labs identified an active Ousaban (Javali) campaign — part of the Brazilian 'Tetrade' banking-trojan family alongside Grandoreiro, Guildma, and Melcoz — targeting bank customers in Spain and Portugal since May 2026. The chain runs a phishing PDF into a fake government tax portal that geofences victims server-side, then uses a VBS downloader to fetch a steganographic image hiding the Ousaban payload, which persists via a 'Financeiro' Run key and harvests banking credentials through overlays, keylogging, clipboard hijacking, and remote-control screenshots.

Ousaban, also tracked as Javali, is one of the four Brazilian banking trojan families (the 'Tetrade': Grandoreiro, Guildma, Melcoz, Ousaban/Javali) documented by Kaspersky since 2020 as having expanded operations beyond Brazil into Latin America and Europe. Active since 2017, Javali historically targeted Mexican banking customers; the campaign analyzed here by FortiGuard Labs (May 2026) represents a resurfaced, Iberian-focused wrapper of the same core malware targeting Spanish and Portuguese bank customers.

The infection chain begins with a phishing email or lure delivering a PDF disguised as a corrupted document. The PDF displays a fake rendering error and an 'Atualizar' (Update) button; clicking it triggers hidden JavaScript that redirects the victim to a malicious webpage impersonating a government tax portal (invoice/'factura' themed). This landing page performs environment profiling and geofencing entirely server-side (an evolution from an earlier, late-2025 variant that performed these checks client-side in JavaScript, making them trivially visible to analysts). The server-side check inspects the visitor's Accept-Language header, timezone, and IP geolocation to restrict the attack to visitors appearing to be in Spain or Portugal; it blocks connections whose IP WHOIS/organization metadata contains the string 'vpn'; and it profiles screen resolution, browser rendering behavior, and installed font enumeration to detect and exclude sandboxes, headless browsers, and automated crawlers used by security researchers.

Visitors who pass all checks are served a VBS (VBScript) downloader. The VBS script fetches an image file styled to resemble a PDF icon; the image uses steganography to conceal an appended ZIP archive containing the Ousaban payload. The script extracts the ZIP, drops the executable into a Temp-folder working directory (observed path pattern C:\SysMain_<random-digits>), executes it, and deletes the staging artifacts to complicate forensic recovery. An empty marker file named maisum.dat is created whose file-creation timestamp is used by the malware as an installation-time reference.

Ousaban establishes persistence by writing a value named 'Financeiro' (Portuguese for 'Financial') to the HKCU\...\CurrentVersion\Run registry key, causing the payload to auto-launch at every Windows logon. Once resident, the trojan remains dormant, monitoring the foreground window/process list until the victim navigates to one of dozens of targeted banking or fintech domains (Santander, BBVA, CaixaBank, Bankinter, Caixa Geral de Depósitos, Revolut, and 19+ others encrypted within the binary). On trigger, Ousaban activates its banking-fraud module: it displays fake overlay/message screens to distract or instruct the victim while performing background fraud, captures full-screen screenshots and streams them to the operator for real-time remote-control ('hands on keyboard') account takeover, logs keystrokes, and hijacks clipboard contents (a classic technique for silently swapping copied bank-account/IBAN numbers with attacker-controlled ones — 'clipper' behavior).

Ousaban's C2 channel is designed to resist static IOC blocking and sinkholing. A decoy Pastebin link is present in the sample and points to a non-routable/dead IP, intended to mislead analysts who pivot on it. The real C2 address is a daily-rotating subdomain computed as 'aki' + the first 8 hex characters of an MD5 hash of a hardcoded secret string concatenated with the current date. To obtain a reliable, tamper-resistant timestamp independent of the victim's local clock, the malware issues a request to Google's 'automated queries' rate-limit/CAPTCHA error page and parses the server-returned date from the HTTP response — an unusual living-off-trusted-services technique for time synchronization that also blends the request into background Google traffic.

Command-and-control communication uses a small tagged-command protocol observed in the sample: #Convite# (collects and exfiltrates victim/system information), #Handle# (assigns a unique victim/session ID), #ON-LINE# (heartbeat/keepalive), #xyScree# (queries victim screen resolution to size overlay windows), and #Iniciar# (initiates screenshot capture and remote-control session). Exfiltrated data and C2 traffic are protected with a custom XOR-based stream cipher: a random initial byte is chosen as a base offset, and each subsequent plaintext byte is XORed against a rotating key byte; when the raw XOR result is numerically smaller than the current base offset, 0xFF is added to the difference before use. Because the initial byte is randomized per session, identical plaintext produces different ciphertext across sessions, defeating naive pattern-based network signatures. Researchers (Li Zhao, Black Duck) note this exact cipher construction is also used by the related Latin American banking trojan Casbaneiro and dates to code shared since at least 2008, indicating Ousaban is an incrementally hardened evolution of long-standing Tetrade tradecraft rather than a technically novel banking trojan.

An earlier, related wave of activity in late 2025 delivered the same malware family via a ClickFix social-engineering lure (fake CAPTCHA/verification prompting victims to paste and run a PowerShell/mshta command) combined with an MSI-based installer, indicating the threat actor iterates delivery mechanisms while reusing the core Ousaban payload and C2 design.

MITRE ATT&CK techniques used in TL-2026-1079

Command and Control

T1001.001 Data Obfuscation: Junk Data; T1071.001 Application Layer Protocol: Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1571 Non-Standard Port; T1573.001 Encrypted Channel: Symmetric Cryptography

Collection

T1005 Data from Local System; T1056.001 Input Capture: Keylogging; T1056.002 Input Capture: GUI Input Capture; T1113 Screen Capture; T1115 Clipboard Data

Discovery

T1010 Application Window Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Software Discovery: Security Software Discovery; T1614.001 System Location Discovery: System Language Discovery

Defense Evasion

T1027.001 Obfuscated Files or Information: Binary Padding; T1027.003 Obfuscated Files or Information: Steganography; T1036.003 Rename Legitimate Utilities; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1497.001 Virtualization/Sandbox Evasion: System Checks

Execution

T1059.005 Command and Scripting Interpreter: Visual Basic; T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File

Persistence

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Initial Access

T1566 Phishing; T1566.001 Phishing: Spearphishing Attachment; T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1587.001 Develop Capabilities: Malware

Reconnaissance

T1589 Gather Victim Identity Information

Impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian

  • Microsoft — Windows (all supported desktop versions)
    Vulnerable versions: Windows 10; Windows 11
  • Multiple — Online banking customers of Iberian financial institutions (Santander, BBVA, CaixaBank, Bankinter, Caixa Geral de Depósitos, Revolut, and 19+ others)
    Vulnerable versions: N/A - social engineering / credential theft target

Weaknesses (CWE) in Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian

CWE-506, CWE-311, CWE-522

Timeline of Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian

  • Javali (Ousaban) first documented as active, initially targeting banking customers in Mexico.
  • Kaspersky publishes 'The Tetrade' research formally grouping Grandoreiro, Guildma, Melcoz, and Ousaban/Javali as related Brazilian banking-trojan families expanding globally.
  • Earlier related campaign wave observed delivering the same malware family via a ClickFix social-engineering lure and MSI-based installer.
  • Prior Ousaban variants observed retrieving live configuration data directly from Pastebin posts, before the operators shifted to the current decoy-Pastebin-plus-DGA C2 design analyzed in the May 2026 campaign.
  • FortiGuard Labs identifies an active Ousaban campaign targeting Iberian (Spain/Portugal) banking customers with the phishing-PDF-to-fake-tax-portal chain and server-side geofencing.
  • Campaign infrastructure observed to have moved geofencing/sandbox-evasion checks from client-side JavaScript (easily inspected) to server-side logic to frustrate analyst review.
  • Netskope publishes research documenting Ousaban and related LATAM banking malware abusing legitimate cloud services (Amazon S3 for payload hosting, Google Docs for C2 configuration retrieval).
  • The Hacker News, Infosecurity Magazine, SC Media, and Cyber Security News publish coverage summarizing the FortiGuard Labs analysis and IOCs.
  • FortiGuard Labs publishes the full technical writeup 'Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula' (authored by Rachael Liao), detailing the PDF-to-VBS-to-steganography chain, C2 protocol tags, and XOR cipher.
  • Campaign surfaced into the Threadlinqs hunt pipeline via RSS coverage of the FortiGuard Labs analysis.

Update history for TL-2026-1079

Sources cited for Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian

Detection coverage for TL-2026-1079

As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1079 across Splunk SPL, Microsoft KQL and Sigma, covering 36 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
36 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1079

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats