Ousaban Malware Uses Phishing PDFs and VBS Downloader to Target Iberian Banking Users
ID: 4e90fb5a-b87a-5f16-957b-aa61bd69cb4b
STIX ID: report--4e90fb5a-b87a-5f16-957b-aa61bd69cb4b
Feed Name: cybersecurityNews.com
Fortinet researchers documented an active Ousaban banking-trojan campaign targeting Windows users in Spain and Portugal. The attack begins with a phishing PDF that either automatically or via user interaction opens a malicious webpage disguised as a tax portal, performs geofencing and sandbox-evasion checks, and delivers a steganographic image containing a ZIP with the Ousaban payload. The malware establishes persistence via a 'Financeiro' registry Run key, remains dormant until victims visit targeted banks, and can capture screenshots, keylogs, clipboard data, and display fake bank screens. Operators use a Pastebin decoy and a daily-rotating C2 domain derived from a Google error-page hash to evade takedowns and automated scanners; Fortinet provides IOCs (registry key, drop path, infrastructure notes) and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
