Fortinet reported an ongoing Ousaban banking Trojan campaign targeting Microsoft Windows users in Spain and Portugal, using phishing PDFs disguised as corrupted documents to redirect victims to malicious webpages. The operation applies geofencing and environment checks to limit infections to Iberian targets, then delivers a VBS script that extracts a hidden ZIP archive from an image and executes the final payload. Researchers said the campaign marks an evolution from late-2025 Ousaban activity that relied on MSI installers and ClickFix-style lures.
Once installed, Ousaban establishes persistence through a Windows Registry Run key named Financeiro and waits for victims to access banking services. The malware supports remote control, keylogging, screenshot capture, clipboard manipulation, and fake on-screen messages to facilitate account takeover. Fortinet said the operators no longer depend on a decoy Pastebin configuration for command-and-control, instead resolving infrastructure through daily changing DDNS hostnames generated from the current date, a tactic that adds resilience and complicates detection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-02, Gurucul published analysis of the ongoing Ousaban campaign that included domains, IP addresses, SHA-256 hashes, and example detection queries. The report also described the malware's execution via DLL side-loading or process injection.
On 2026-07-01, FortiGuard Labs published an analysis describing the ongoing Ousaban attacks targeting the Iberian Peninsula, including the malware's persistence, banking-focused monitoring, and date-derived daily changing command-and-control hostnames.
The May 2026 campaign redirected victims from phishing PDFs to malicious webpages that downloaded a VBS script, which extracted a ZIP archive hidden inside an image and executed the final Ousaban payload. Fortinet said this reflected an evolution in the malware's delivery chain.
In May 2026, operators behind the Brazilian banking trojan Ousaban targeted Microsoft Windows users in Spain and Portugal with phishing PDFs posing as corrupted files. The campaign used geofencing and environment checks to limit payload delivery to intended Iberian victims.
Fortinet reported that Ousaban activity observed in late 2025 used earlier delivery methods, including MSI installers and ClickFix-style lures, before the campaign evolved to newer phishing techniques.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcefeeds.fortinet.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.