Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula
ID: 9ffcdd40-797a-5fd5-8ba0-adfe87d3fff4
STIX ID: report--9ffcdd40-797a-5fd5-8ba0-adfe87d3fff4
Feed Name: Fortinet Blog
Threat Score
FortiGuard Labs documents a high-severity campaign distributing the banking Trojan Ousaban against users in Spain and Portugal via phishing PDFs and malicious webpages; the attack chain uses a VBS downloader, steganographic image/ZIP delivery, MSI/EXE payloads, DLL side-loading or process injection for execution, daily-changing DDNS-based C2 hostnames with custom encryption, and persistence mechanisms, and the report includes domains, IPs, and file hashes as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
