Ousaban Banking Trojan Targets Spain and Portugal
ID: 3686ec5d-d15b-5303-b293-154377d64fe4
STIX ID: report--3686ec5d-d15b-5303-b293-154377d64fe4
Feed Name: securityonline.info
Threat Score
FortiGuard Labs reports a May 2026 campaign distributing the Ousaban banking trojan targeting banking customers in Spain and Portugal via geo-fenced phishing PDFs and fake tax portals; the attack chain drops a VBS that retrieves a steganographic PNG to extract a ZIP and EXE, establishes persistence (Run key value "Financeiro"), and enables credential theft through keylogging, screen overlays, and clipboard injection while using dynamic C2 resolution and custom encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
