# Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and Steganographic VBS Downloader

> FortiGuard Labs identified an active Ousaban (Javali) campaign — part of the Brazilian 'Tetrade' banking-trojan family alongside Grandoreiro, Guildma, and Melcoz — targeting bank customers in Spain and Portugal since May 2026. The chain runs a phishing PDF into a fake government tax portal that geofences victims server-side, then uses a VBS downloader to fetch a steganographic image hiding the Ousaban payload, which persists via a 'Financeiro' Run key and harvests banking credentials through overlays, keylogging, clipboard hijacking, and remote-control screenshots.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-23T07:09:15.584Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1079
- **ID:** TL-2026-1079
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Tetrade (Brazil)
- **Detections:** 9 · **IOCs:** 36 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Ousaban, also tracked as Javali, is one of the four Brazilian banking trojan families (the 'Tetrade': Grandoreiro, Guildma, Melcoz, Ousaban/Javali) documented by Kaspersky since 2020 as having expanded operations beyond Brazil into Latin America and Europe. Active since 2017, Javali historically targeted Mexican banking customers; the campaign analyzed here by FortiGuard Labs (May 2026) represents a resurfaced, Iberian-focused wrapper of the same core malware targeting Spanish and Portuguese bank customers.

The infection chain begins with a phishing email or lure delivering a PDF disguised as a corrupted document. The PDF displays a fake rendering error and an 'Atualizar' (Update) button; clicking it triggers hidden JavaScript that redirects the victim to a malicious webpage impersonating a government tax portal (invoice/'factura' themed). This landing page performs environment profiling and geofencing entirely server-side (an evolution from an earlier, late-2025 variant that performed these checks client-side in JavaScript, making them trivially visible to analysts). The server-side check inspects the visitor's Accept-Language header, timezone, and IP geolocation to restrict the attack to visitors appearing to be in Spain or Portugal; it blocks connections whose IP WHOIS/organization metadata contains the string 'vpn'; and it profiles screen resolution, browser rendering behavior, and installed font enumeration to detect and exclude sandboxes, headless browsers, and automated crawlers used by security researchers.

Visitors who pass all checks are served a VBS (VBScript) downloader. The VBS script fetches an image file styled to resemble a PDF icon; the image uses steganography to conceal an appended ZIP archive containing the Ousaban payload. The script extracts the ZIP, drops the executable into a Temp-folder working directory (observed path pattern C:\SysMain_<random-digits>), executes it, and deletes the staging artifacts to complicate forensic recovery. An empty marker file named maisum.dat is created whose file-creation timestamp is used by the malware as an installation-time reference.

Ousaban establishes persistence by writing a value named 'Financeiro' (Portuguese for 'Financial') to the HKCU\...\CurrentVersion\Run registry key, causing the payload to auto-launch at every Windows logon. Once resident, the trojan remains dormant, monitoring the foreground window/process list until the victim navigates to one of dozens of targeted banking or fintech domains (Santander, BBVA, CaixaBank, Bankinter, Caixa Geral de Depósitos, Revolut, and 19+ others encrypted within the binary). On trigger, Ousaban activates its banking-fraud module: it displays fake overlay/message screens to distract or instruct the victim while performing background fraud, captures full-screen screenshots and streams them to the operator for real-time remote-control ('hands on keyboard') account takeover, logs keystrokes, and hijacks clipboard contents (a classic technique for silently swapping copied bank-account/IBAN numbers with attacker-controlled ones — 'clipper' behavior).

Ousaban's C2 channel is designed to resist static IOC blocking and sinkholing. A decoy Pastebin link is present in the sample and points to a non-routable/dead IP, intended to mislead analysts who pivot on it. The real C2 address is a daily-rotating subdomain computed as 'aki' + the first 8 hex characters of an MD5 hash of a hardcoded secret string concatenated with the current date. To obtain a reliable, tamper-resistant timestamp independent of the victim's local clock, the malware issues a request to Google's 'automated queries' rate-limit/CAPTCHA error page and parses the server-returned date from the HTTP response — an unusual living-off-trusted-services technique for time synchronization that also blends the request into background Google traffic.

Command-and-control communication uses a small tagged-command protocol observed in the sample: #Convite# (collects and exfiltrates victim/system information), #Handle# (assigns a unique victim/session ID), #ON-LINE# (heartbeat/keepalive), #xyScree# (queries victim screen resolution to size overlay windows), and #Iniciar# (initiates screenshot capture and remote-control session). Exfiltrated data and C2 traffic are protected with a custom XOR-based stream cipher: a random initial byte is chosen as a base offset, and each subsequent plaintext byte is XORed against a rotating key byte; when the raw XOR result is numerically smaller than the current base offset, 0xFF is added to the difference before use. Because the initial byte is randomized per session, identical plaintext produces different ciphertext across sessions, defeating naive pattern-based network signatures. Researchers (Li Zhao, Black Duck) note this exact cipher construction is also used by the related Latin American banking trojan Casbaneiro and dates to code shared since at least 2008, indicating Ousaban is an incrementally hardened evolution of long-standing Tetrade tradecraft rather than a technically novel banking trojan.

An earlier, related wave of activity in late 2025 delivered the same malware family via a ClickFix social-engineering lure (fake CAPTCHA/verification prompting victims to paste and run a PowerShell/mshta command) combined with an MSI-based installer, indicating the threat actor iterates delivery mechanisms while reusing the core Ousaban payload and C2 design.

## MITRE ATT&CK

- T1566 Phishing
- T1566.001 Phishing: Spearphishing Attachment
- T1566.002 Phishing: Spearphishing Link
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1204.002 User Execution: Malicious File
- T1204.001 User Execution: Malicious Link
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1027.003 Obfuscated Files or Information: Steganography
- T1140 Deobfuscate/Decode Files or Information
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1070.004 Indicator Removal: File Deletion
- T1036.005 Match Legitimate Resource Name or Location
- T1036.003 Rename Legitimate Utilities
- T1685 Disable or Modify Tools
- T1082 System Information Discovery
- T1614.001 System Location Discovery: System Language Discovery
- T1010 Application Window Discovery
- T1057 Process Discovery
- T1518.001 Software Discovery: Security Software Discovery
- T1113 Screen Capture
- T1056.001 Input Capture: Keylogging
- T1056.002 Input Capture: GUI Input Capture
- T1115 Clipboard Data
- T1005 Data from Local System
- T1071.001 Application Layer Protocol: Web Protocols
- T1568.002 Dynamic Resolution: Domain Generation Algorithms
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1001.001 Data Obfuscation: Junk Data
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1571 Non-Standard Port
- T1657 Financial Theft
- T1583.001 Acquire Infrastructure: Domains
- T1587.001 Develop Capabilities: Malware
- T1589 Gather Victim Identity Information
- T1027.001 Obfuscated Files or Information: Binary Padding
- T1219 Remote Access Tools

## Sources

- [Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula](https://www.fortinet.com/blog/threat-research/analysis-of-ongoing-ousaban-attacks-targeting-the-iberian-peninsula)
- [Ousaban Malware Uses Phishing PDFs and VBS Downloader](https://cybersecuritynews.com/ousaban-malware-uses-phishing-pdfs-and-vbs-downloader/)
- [Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures](https://thehackernews.com/2026/07/ousaban-banking-trojan-targets-iberian.html)
- [Brazilian Banking Trojan Ousaban Targets Spain and Portugal](https://www.infosecurity-magazine.com/news/ousaban-banking-trojan-spain/)
- [Ousaban banking trojan targets Spain and Portugal with new stealth techniques](https://www.scworld.com/brief/ousaban-banking-trojan-targets-spain-and-portugal-with-new-stealth-techniques)
- [The Tetrade: Brazilian banking malware goes global](https://securelist.com/the-tetrade-brazilian-banking-malware/97779/)
- [Arrests of members of Tetrade seed groups Grandoreiro and Melcoz](https://securelist.com/arrests-of-members-of-tetrade-seed-groups-grandoreiro-and-melcoz/103366/)
- ['Tetrade' Brazilian Banking Trojans Go International](https://www.securityweek.com/tetrade-brazilian-banking-trojans-go-international/)
- [Tetrade banking malware families target users worldwide](https://securityaffairs.com/106126/malware/tetrade-brazilian-banking-troja.html)
- [Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures](https://news.cybertechworld.co.in/index.php/2026/07/01/ousaban-banking-trojan-targets-iberian-bank-users-with-fake-pdf-lures/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1079
