Fortinet's FortiGuard Labs has identified an active campaign by Ousaban (also known as Javali), a Brazilian banking trojan targeting Windows users in Spain and Portugal. The attack uses phishing PDFs disguised as corrupted files, prompting victims to click an 'Update' button or triggering a malicious page automatically via hidden JavaScript. Server-side geofencing blocks anyone outside Spain and Portugal or using VPNs. The payload is hidden inside an image using steganography, unpacked from a ZIP, and installed with a Windows registry persistence key named 'Financeiro.' Once active, Ousaban captures keystrokes and screenshots, manipulates the clipboard, and grants attackers remote control when banking sites are visited — targeting over two dozen banks including Santander, BBVA, and CaixaBank. The malware evades blocklists by computing a new command server address daily using the current date and a fixed secret. Ousaban is part of the Brazilian 'Tetrade' group alongside Grandoreiro, Guildma, and Melcoz, all of which have expanded from Brazil into the Iberian Peninsula.

3m read timeFrom thenextweb.com
Post cover image
29 Impressions