logo

Ousaban Banking Trojan Targets Spain and Portugal

ID: 3686ec5d-d15b-5303-b293-154377d64fe4

STIX ID: report--3686ec5d-d15b-5303-b293-154377d64fe4

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-07-06

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

FortiGuard Labs reports a May 2026 campaign distributing the Ousaban banking trojan targeting banking customers in Spain and Portugal via geo-fenced phishing PDFs and fake tax portals; the attack chain drops a VBS that retrieves a steganographic PNG to extract a ZIP and EXE, establishes persistence (Run key value "Financeiro"), and enables credential theft through keylogging, screen overlays, and clipboard injection while using dynamic C2 resolution and custom encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.