Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain — Threadlinqs Intelligence
As of 2026-09-03, Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain is a high-severity malware threat attributed to a Brazil-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-2305 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Brazil · FINANCIAL
An ongoing campaign, first identified by FortiGuard Labs in May 2026, delivers the Brazilian Ousaban (aka Javali) banking Trojan to Windows users banking in Spain and Portugal through a phishing PDF,
Ousaban (also tracked as Javali) is a Delphi-based Brazilian banking Trojan belonging to the "Tetrade" cluster of related LATAM banking malware families identified by Kaspersky, alongside Grandoreiro, Guildma/Astaroth, and Melcoz. Historically focused on Brazilian financial institutions, FortiGuard Labs identified an expansion of the family's operators into Spain and Portugal in May 2026, publishing a detailed writeup on July 1, 2026.
The attack begins with a phishing PDF disguised as a corrupted file that displays a deceptive "Atualizar" (Update) button and contains hex-escaped JavaScript. Clicking the button routes the victim to a geofenced landing page masquerading as a tax document or installer source; the page performs server-side environmental checks (IP address, browser language, timezone, screen resolution, rendering behavior, and font enumeration) and blocks requests containing VPN-related keywords, serving either an error or the next-stage download depending on the check outcome.
Successful checks deliver a VBS downloader that mixes benign function calls with malicious logic, extracts a steganographic image disguised as a PDF icon, decodes an embedded ZIP archive from the image, and drops the Ousaban payload to C:\SysMain_5874288 before self-deleting. Ousaban establishes persistence via a "Financeiro" value under the Registry Run key, tracks execution timestamps in a maisum.dat file, and decrypts a hardcoded list of 13+ targeted Spanish and Portuguese banks (including Banco Santander, BBVA, CaixaBank, Bankinter, and Caixa Geral de Depósitos) using the same custom XOR-plus-offset algorithm documented in the Casbaneiro Trojan. Once active, it provides keylogging, clipboard injection, screenshot capture, fake on-screen message generation, and full remote mouse/keyboard control to the operator.
Command and control uses DDNS subdomains that rotate daily, computed as a hardcoded "aki" prefix concatenated with the first eight characters of an MD5 hash derived from a fixed secret string and the current date; the malware fetches the current date via an intentional request to a Google Automated Queries page. Configuration and decoy data are staged on Pastebin, consistent with the broader Ousaban family's documented history of abusing legitimate cloud services (Amazon S3, Google Docs, Google Cloud Run) for payload hosting and C2 configuration retrieval in earlier LATAM-focused campaigns dating back to at least 2021.
Target sectors: finance
Target regions: spain, portugal
Timeline
- ESET Research publishes the first major public analysis of the Ousaban banking Trojan family, documenting its history of hiding payloads inside media files, protecting executables with Themida/Enigma packers, and using binary padding for evasion.
- Netskope documents Ousaban abusing Amazon S3 and Google Docs to host second-stage payloads and retrieve C2 configuration in Brazil-focused campaigns.
- Cisco Talos reports Ousaban, alongside Astaroth/Guildma and Mekotio, abusing Google Cloud Run for high-volume malware distribution across Latin America and Europe, with activity observed since September 2023.
- FortiGuard Labs first identifies the Ousaban campaign targeting Windows users banking in Spain and Portugal (month-level precision per source, exact day not disclosed).
- Campaign delivery begins with phishing PDFs disguised as corrupted documents, featuring a deceptive "Atualizar" (Update) button and hex-escaped embedded JavaScript.
- Victims clicking the PDF's link are routed to a geofenced landing page that performs server-side IP, language, timezone, screen-resolution, and font-enumeration checks and blocks requests containing VPN-related keywords.
- The landing page serves a VBS downloader that extracts a steganographic image resembling a PDF icon, decodes an embedded ZIP archive, and drops the Ousaban payload to C:\SysMain_5874288.
- Ousaban establishes persistence via a "Financeiro" Registry Run key value and begins timestamp tracking through a maisum.dat file.
- Ousaban begins beaconing to daily-rotating DDNS subdomains (prefix "aki" plus an 8-character MD5 hash derived from a hardcoded string and the current date) and retrieves configuration data staged on Pastebin.
- FortiGuard Labs publishes a detailed public analysis of the ongoing Iberian Ousaban campaign, releasing IOCs covering 5 domains, 4 IPs, and 20 file hashes.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.001, T1204.001, T1204.002, T1059.005, T1218.007, T1547.001, T1027.003, T1140, T1497.001, T1070.004