FortiGuard Labs details an active Ousaban banking Trojan campaign targeting users in Spain and Portugal. The attack chain begins with a phishing PDF disguised as a corrupted file, directing victims to a geofenced malicious webpage that performs server-side environment checks (IP, language, timezone, VPN detection, browser fingerprinting) before delivering a VBS downloader. The VBS script retrieves a steganographic image containing a hidden ZIP archive with the Ousaban payload. Once executed, Ousaban establishes persistence via a registry Run key, monitors browser access to specific banks, and resolves its C2 address through daily-rotating DDNS hostnames derived from an MD5 hash of a hard-coded string and the current date — using Google's Automated Queries page to obtain the date. A Pastebin link containing a private IP serves as a decoy. The malware supports screenshot capture, keylogging, clipboard injection, and remote control. The post includes full IOCs (domains, IPs, file hashes) and details the custom XOR-based encryption algorithm shared with other Latin American banking Trojans like Casbaneiro.

9m read timeFrom feeds.fortinet.com
Post cover image
Table of contents
PDFHTMLVBSOusabanPastebinConclusionFortinet ProtectionsIOCs
110 Impressions