logo

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

ID: 9ffcdd40-797a-5fd5-8ba0-adfe87d3fff4

STIX ID: report--9ffcdd40-797a-5fd5-8ba0-adfe87d3fff4

Feed Name: Fortinet Blog

Threat Score
75/100

Date Published: 2026-07-01

Date Updated: 2026-07-02

...
...

FortiGuard Labs documents a high-severity campaign distributing the banking Trojan Ousaban against users in Spain and Portugal via phishing PDFs and malicious webpages; the attack chain uses a VBS downloader, steganographic image/ZIP delivery, MSI/EXE payloads, DLL side-loading or process injection for execution, daily-changing DDNS-based C2 hostnames with custom encryption, and persistence mechanisms, and the report includes domains, IPs, and file hashes as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.