Ousaban, also tracked as Javali, is a Delphi-based Latin American banking trojan associated with Brazilian cybercrime activity and active since at least 2018, with indications of emergence between 2017 and 2018. It historically targeted victims in Brazil, especially customers of financial institutions, and later expanded to campaigns aimed at banking users in Spain and Portugal. Ousaban is part of the broader ecosystem of Brazilian banking malware and shares code, obfuscation, delivery patterns, and operational tradecraft with families such as Casbaneiro, Grandoreiro, Guildma, Mekotio, Vadokrist, Amavaldo, and Mispadu.
Its core objective is banking fraud and theft of sensitive financial information. Ousaban monitors active window titles or other indicators of access to targeted banking services and typically activates only when the victim interacts with a targeted institution. Documented capabilities include credential theft through fake banking overlays or deceptive screens, keylogging, screenshot capture, clipboard manipulation, and remote operator interaction through simulated mouse and keyboard control. Some variants also include broader backdoor-style functionality and victim profiling. Command-and-control communications and protected strings are encrypted, and the malware has used custom string-encryption schemes common among Latin American banking trojans as well as AES-encrypted communications in some observed variants.
Ousaban is notable for layered delivery chains and strong emphasis on defense evasion. Distribution has primarily relied on phishing, often using malicious MSI installers delivered directly or via archives. Observed chains include MSI packages that launch obfuscated JavaScript or VBScript downloaders, retrieval of staged payloads from cloud services, and execution through DLL side-loading with signed or legitimate binaries. Other campaigns used CAB or ZIP archives, encrypted injectors and downloaders, and multistage loaders that decrypt the final banking trojan from disk. More recent campaigns targeting Iberian users used phishing PDFs disguised as corrupted documents, malicious tax-themed landing pages, server-side geofencing, VPN and sandbox screening, and steganography to conceal payload archives inside image files. Late-2025 activity also included ClickFix-style social engineering and Rust-based downloaders embedded in MSI installers.
The malware commonly employs obfuscation and anti-analysis measures including Themida or Enigma protection, binary padding, dynamic API resolution, encrypted configuration, staged payload decryption, and selective activation only after banking activity is detected. It has used remote configuration hosted on public platforms including Google Docs, YouTube, and Pastebin, though some embedded configuration references have served as decoys. In 2026 reporting, Ousaban was observed resolving its real command infrastructure through daily changing dynamic DNS hostnames derived from the current date, complicating static blocking and analysis.
Persistence on Windows has been achieved through Startup-folder artifacts or Run-key modification, and some multistage chains included a support module that altered remote access and firewall settings and created a new administrative account to facilitate secondary access. Ousaban therefore spans both classic banking-trojan fraud functions and post-compromise remote access tradecraft. Its campaigns have primarily targeted Windows users and financial institutions, with especially strong focus on Brazilian banking customers and, more recently, bank users in Spain and Portugal.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Ousaban uses the cmd.exe to execute the legitimate applications that side-load the main Ousaban payload.
In the first scenario, the JavaScript is executed via CustomAction. The JavaScript code is obfuscated, likely in an attempt to slow down analysis.
Potential victims need to follow steps required to install the malware on their machines
The JavaScript code is obfuscated, likely in an attempt to slow down analysis... Aside from decrypting the payload, the second stage also decrypts the code that will execute Ousaban in runtime, probably to slow down reverse engineering... Ousaban commonly packs/protects its payloads with UPX or Enigma.
most EXEs are enlarged, using binary padding, to approximately 400 MB, likely in order to evade detection and automated processing.
Important API calls used by this stage are also dynamically resolved, another common technique to slow down reverse engineering.
The injector locates, decrypts and executes the downloader. The downloader decrypts the configuration file... Ousaban payloads and strings are encrypted.
“avisoProtesto.exe” is a signed and non-malicious binary exploited to execute the malicious DLL via DLL search order hijacking.
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
Like other Brazilian-sourced malware, Ousaban monitors the title text from the active window and compares it with a list of strings, to verify if the victim is accessing the website or an application of one of its targets.
Sends a simple GET request to another URL (Azure or another attacker-controlled server), alerting the attacker and logging the victim’s IP;
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
Its backdoor capabilities are very similar to a typical Latin American banking trojan – simulating mouse and keyboard actions and logging keystrokes.
the threat often abuses cloud services, such as Amazon S3 to download second stage payloads, and Google Docs to retrieve the C2 configuration... the malware is using Pastebin to fetch the data... contain a routine to communicate via Telegram using Webhooks
Downloads the second stage from the cloud, either from Amazon or Azure; Decompress the ZIP file downloaded from the cloud and renames the main executable;
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking trojan/RAT used in a geofenced campaign against users in Spain and Portugal. It is delivered via phishing PDFs, a malicious web page, VBS downloader, and steganographic image/ZIP stages, then establishes persistence, monitors access to targeted banks, and supports screenshot capture, remote control, keylogging, clipboard injection, and dynamic DDNS-based C2 resolution.
Brazilian banking trojan targeting bank customers in Spain and Portugal. It is delivered via phishing PDFs and a VBS-style downloader, uses geofencing and steganography to evade analysis, establishes persistence via a Windows Run key, and steals banking credentials through screenshots, keylogging, clipboard tampering, and fake banking screens.
A banking trojan historically active in Brazil that, in this campaign, targets users in Spain and Portugal via phishing PDFs, a malicious MSI/VBS-based delivery chain, and execution through DLL side-loading or process injection.
Brazilian banking trojan targeting Windows users in Spain and Portugal via phishing PDFs and a malicious webpage. It uses geofencing and steganography to evade detection, then steals banking credentials by capturing screenshots, logging keystrokes, and manipulating clipboard data when victims access targeted banking sites.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.