Fortinet's FortiGuard Labs has identified an active campaign by Ousaban (also known as Javali), a Brazilian banking trojan targeting Windows users in Spain and Portugal. The attack uses phishing PDFs disguised as corrupted files, prompting victims to click an 'Update' button or triggering a malicious page automatically via hidden JavaScript. Server-side geofencing blocks anyone outside Spain and Portugal or using VPNs. The payload is hidden inside an image using steganography, unpacked from a ZIP, and installed with a Windows registry persistence key named 'Financeiro.' Once active, Ousaban captures keystrokes and screenshots, manipulates the clipboard, and grants attackers remote control when banking sites are visited — targeting over two dozen banks including Santander, BBVA, and CaixaBank. The malware evades blocklists by computing a new command server address daily using the current date and a fixed secret. Ousaban is part of the Brazilian 'Tetrade' group alongside Grandoreiro, Guildma, and Melcoz, all of which have expanded from Brazil into the Iberian Peninsula.