Ousaban, also known as Javali, is a Delphi-based banking trojan targeting Microsoft Windows. Active since at least 2018, it historically focused on Brazilian banking customers and regional email services. Campaigns observed from May 2026 extended its targeting to banking customers in Spain and Portugal. Its principal objective is credential theft and financial fraud through deceptive banking overlays and operator-controlled interaction with infected systems.
Ousaban monitors active window titles to identify access to targeted financial services and activates its command-and-control functions when a matching service is detected. Its capabilities include keylogging, screenshot capture, mouse and keyboard control, clipboard manipulation, victim-information collection, and fake banking screens that solicit sensitive information. It establishes persistence through Windows startup mechanisms or registry Run entries. Some distribution chains include a support module that enables remote desktop access, adjusts firewall settings, and creates a local administrator account for secondary access.
Delivery primarily uses phishing emails, malicious PDFs, MSI installers, and multistage script downloaders. Established chains abuse signed legitimate applications for DLL side-loading and retrieve encrypted payloads from cloud-hosted archives. Other observed delivery mechanisms include malicious advertisements and ClickFix lures. The 2026 Iberian campaigns used corrupted-document lures directing victims to tax-themed webpages, where server-side geographic and environmental checks restricted delivery and screened out VPN connections and analysis environments. A script downloader extracted the payload from an archive concealed inside an image and removed intermediate installation artifacts.
Ousaban employs string encryption, encrypted communications, executable protectors, binary padding, and dynamic API resolution to hinder detection and analysis. Earlier variants retrieved remote configuration from public web services; the 2026 Iberian campaign used daily generated dynamic-DNS hostnames and a decoy configuration link. It shares encryption techniques and distribution patterns with other Latin American banking trojans, including Casbaneiro, Grandoreiro, and Guildma.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
Ousaban uses the cmd.exe to execute the legitimate applications that side-load the main Ousaban payload.
Files associated with the distribution domain included VBS files responsible for downloading the next stage; in the Ousaban chain, the VBS file executes the final payload.
In the first scenario, the JavaScript is executed via CustomAction. The JavaScript code is obfuscated, likely in an attempt to slow down analysis.
Potential victims need to follow steps required to install the malware on their machines
The decryption key and encrypted strings are split into multiple fragments, which are concatenated at runtime whenever the malware needs to decrypt and use a specific string.
most EXEs are enlarged, using binary padding, to approximately 400 MB, likely in order to evade detection and automated processing.
The VBS file retrieves a steganographic PNG image mimicking a PDF document, from which it extracts a ZIP file containing the Ousaban DLL.
Important API calls used by this stage are also dynamically resolved, another common technique to slow down reverse engineering.
The Ousaban final payload is run via DLL sideloading or process injection.
The injector locates, decrypts and executes the downloader. The downloader decrypts the configuration file... Ousaban payloads and strings are encrypted.
“avisoProtesto.exe” is a signed and non-malicious binary exploited to execute the malicious DLL via DLL search order hijacking.
Like other Brazilian-sourced malware, Ousaban monitors the title text from the active window and compares it with a list of strings, to verify if the victim is accessing the website or an application of one of its targets.
Sends a simple GET request to another URL (Azure or another attacker-controlled server), alerting the attacker and logging the victim’s IP;
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
the threat often abuses cloud services, such as Amazon S3 to download second stage payloads, and Google Docs to retrieve the C2 configuration... the malware is using Pastebin to fetch the data... contain a routine to communicate via Telegram using Webhooks
Downloads the second stage from the cloud, either from Amazon or Azure; Decompress the ZIP file downloaded from the cloud and renames the main executable;
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sample was delivered from caixaentradas1inboxshop.site, a delivery domain also discussed in the BraZetsu reporting. The article distinguishes that delivery phase from the newly identified panel and C2 host. It provides no further Ousaban capability, operator or vulnerability details.
Banking malware mentioned as a comparison because it similarly waits for victims to visit selected banking sites before acting.
Banking malware mentioned only as a comparison for its behavior of waiting until victims open selected banking sites.
Banking Trojan observed being delivered from infrastructure also associated with BraZetsu distribution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.