Ousaban is a Brazilian banking trojan targeting Microsoft Windows systems. In May 2026, FortiGuard Labs reported an active campaign focused on users in Spain and Portugal, particularly Iberian bank customers. The infection chain used phishing PDFs disguised as corrupted files that prompted victims to click an "Atualizar" (Update) button; hidden JavaScript in the PDF could also redirect to the same malicious page. The landing page impersonated a tax-document or installer portal and applied geofencing and environment checks, including location, language, time zone, IP/VPN characteristics, and other browser or host profiling, with newer variants moving screening logic server-side to restrict delivery to likely victims in Spain and Portugal.
If validation succeeded, the site delivered a VBS downloader that retrieved a steganographic image resembling a PDF icon. That image concealed a ZIP archive containing the Ousaban payload, which was extracted and executed from C:\SysMain_5874288; the VBS, image, and ZIP artifacts were then deleted. Ousaban established persistence via a Windows Run key value named "Financeiro" under CurrentVersion\Run and created an empty file named "maisum.dat" as an installation marker. The malware remained dormant until the victim accessed targeted banking services, including banks such as Santander, BBVA, CaixaBank, Bankinter, and Caixa Geral de Depósitos.
Documented capabilities include keylogging, screenshot capture, clipboard injection/manipulation, victim profiling, heartbeat signaling, victim ID handling, screen resolution reporting, remote control, mouse and keyboard control, and fake-message or fake-bank-screen deception during banking sessions. Ousaban decrypts bank-related strings to monitor targeted services and uses a custom XOR-based encryption scheme described as shared with other Latin American banking trojans such as Casbaneiro. For command-and-control, the malware used dynamic DNS with daily changing subdomains generated from an MD5-based algorithm using the current date and a hardcoded string; Fortinet reported that a decrypted Pastebin configuration containing a private IP acted as a decoy, while actual C2 resolution relied on DDNS domains. Late-2025 variants reportedly used ClickFix lures and MSI installers containing a Rust-based downloader.
High-confidence infrastructure and host indicators mentioned in the reporting include domains faturanova.xyz, facture-in.pages.dev, facture-arsys.duckdns.org, faturanova.duckdns.org, and controlfacturas.site; IP addresses 213.159.64.191, 162.33.179.46, 91.92.240.140, and 78.40.209.32; dropped path C:\SysMain_5874288; persistence value "Financeiro"; and marker file "maisum.dat".
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Hidden JavaScript inside the phishing PDF can open the malicious webpage automatically, so even a cautious click is not always required.
Any PDF or email claiming a file is corrupted and asking the reader to click Update should be treated as hostile, along with prompts asking users to paste a command to fix an error, a tactic known as ClickFix.
Il contient de nombreux appels de fonctions bénins pour masquer le code malveillant
puis télécharge une image stéganographique (ressemblant à une icône PDF) contenant un fichier ZIP avec le payload Ousaban.
Most of the traffic between the server and Ousaban is encrypted using the previously described algorithm.
The malware then deletes the traces of its own installation to make detection harder for anyone reviewing the machine later.
Elle effectue des vérifications d’environnement côté serveur (langue, fuseau horaire, IP, résolution d’écran, rendu navigateur, énumération de polices) pour restreindre l’accès
Elle effectue des vérifications d’environnement côté serveur (langue, fuseau horaire, IP, résolution d’écran, rendu navigateur, énumération de polices) pour restreindre l’accès
At that point it can capture screenshots, log keystrokes, tamper with the clipboard, and display fake bank screens to trick users into handing over login details.
#Iniciar# (capture d’écran, contrôle à distance, keylogger, injection clipboard)
If the hostname is resolvable, Ousaban establishes a connection to the C2 server.
Résolution C2 dynamique : utilisation de DDNS avec sous-domaines changeant quotidiennement
The real address changes every day, generated from a hash of the current date pulled off a Google error page, which makes blocking yesterday’s domain pointless.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking trojan/RAT used in a geofenced campaign against users in Spain and Portugal. It is delivered via phishing PDFs, a malicious web page, VBS downloader, and steganographic image/ZIP stages, then establishes persistence, monitors access to targeted banks, and supports screenshot capture, remote control, keylogging, clipboard injection, and dynamic DDNS-based C2 resolution.
Brazilian banking trojan targeting bank customers in Spain and Portugal. It is delivered via phishing PDFs and a VBS-style downloader, uses geofencing and steganography to evade analysis, establishes persistence via a Windows Run key, and steals banking credentials through screenshots, keylogging, clipboard tampering, and fake banking screens.
A banking trojan historically active in Brazil that, in this campaign, targets users in Spain and Portugal via phishing PDFs, a malicious MSI/VBS-based delivery chain, and execution through DLL side-loading or process injection.
Brazilian banking trojan targeting Windows users in Spain and Portugal via phishing PDFs and a malicious webpage. It uses geofencing and steganography to evade detection, then steals banking credentials by capturing screenshots, logging keystrokes, and manipulating clipboard data when victims access targeted banking sites.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.