Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and Steganographic VBS Downloader — Threadlinqs Intelligence
As of 2026-07-23, Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and Steganographic VBS Downloader is a high-severity malware threat attributed to Tetrade (Ousaban (Brazil), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 36 indicators of compromise.
Threat ID: TL-2026-1079 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Updated: 2026-07-23 · revalidated 1× · latest source
Attribution: Tetrade (Ousaban · Brazil · FINANCIAL
FortiGuard Labs identified an active Ousaban (Javali) campaign — part of the Brazilian 'Tetrade' banking-trojan family alongside Grandoreiro, Guildma, and Melcoz — targeting bank customers in Spain
Ousaban, also tracked as Javali, is one of the four Brazilian banking trojan families (the 'Tetrade': Grandoreiro, Guildma, Melcoz, Ousaban/Javali) documented by Kaspersky since 2020 as having expanded operations beyond Brazil into Latin America and Europe. Active since 2017, Javali historically targeted Mexican banking customers; the campaign analyzed here by FortiGuard Labs (May 2026) represents a resurfaced, Iberian-focused wrapper of the same core malware targeting Spanish and Portuguese bank customers.
The infection chain begins with a phishing email or lure delivering a PDF disguised as a corrupted document. The PDF displays a fake rendering error and an 'Atualizar' (Update) button; clicking it triggers hidden JavaScript that redirects the victim to a malicious webpage impersonating a government tax portal (invoice/'factura' themed). This landing page performs environment profiling and geofencing entirely server-side (an evolution from an earlier, late-2025 variant that performed these checks client-side in JavaScript, making them trivially visible to analysts). The server-side check inspects the visitor's Accept-Language header, timezone, and IP geolocation to restrict the attack to visitors appearing to be in Spain or Portugal; it blocks connections whose IP WHOIS/organization metadata contains the string 'vpn'; and it profiles screen resolution, browser rendering behavior, and installed font enumeration to detect and exclude sandboxes, headless browsers, and automated crawlers used by security researchers.
Visitors who pass all checks are served a VBS (VBScript) downloader. The VBS script fetches an image file styled to resemble a PDF icon; the image uses steganography to conceal an appended ZIP archive containing the Ousaban payload. The script extracts the ZIP, drops the executable into a Temp-folder working directory (observed path pattern C:\SysMain_<random-digits>), executes it, and deletes the staging artifacts to complicate forensic recovery. An empty marker file named maisum.dat is created whose file-creation timestamp is used by the malware as an installation-time reference.
Ousaban establishes persistence by writing a value named 'Financeiro' (Portuguese for 'Financial') to the HKCU\...\CurrentVersion\Run registry key, causing the payload to auto-launch at every Windows logon. Once resident, the trojan remains dormant, monitoring the foreground window/process list until the victim navigates to one of dozens of targeted banking or fintech domains (Santander, BBVA, CaixaBank, Bankinter, Caixa Geral de Depósitos, Revolut, and 19+ others encrypted within the binary). On trigger, Ousaban activates its banking-fraud module: it displays fake overlay/message screens to distract or instruct the victim while performing background fraud, captures full-screen screenshots and streams them to the operator for real-time remote-control ('hands on keyboard') account takeover, logs keystrokes, and hijacks clipboard contents (a classic technique for silently swapping copied bank-account/IBAN numbers with attacker-controlled ones — 'clipper' behavior).
Ousaban's C2 channel is designed to resist static IOC blocking and sinkholing. A decoy Pastebin link is present in the sample and points to a non-routable/dead IP, intended to mislead analysts who pivot on it. The real C2 address is a daily-rotating subdomain computed as 'aki' + the first 8 hex characters of an MD5 hash of a hardcoded secret string concatenated with the current date. To obtain a reliable, tamper-resistant timestamp independent of the victim's local clock, the malware issues a request to Google's 'automated queries' rate-limit/CAPTCHA error page and parses the server-returned date from the HTTP response — an unusual living-off-trusted-services technique for time synchronization that also blends the request into background Google traffic.
Command-and-control communication uses a small tagged-command protocol observed in the sample: #Convite# (collects and exfi
Weaknesses (CWE)
CWE-506, CWE-311, CWE-522
Target sectors: finance, banking
Target regions: spain, portugal, Iberian Peninsula, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 36 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1566.001, T1566.002, T1059.005, T1204.002, T1204.001, T1547.001, T1027.003, T1140, T1497.001