Threats · 75 days ago
This campaign can look quiet from outside Spain and Portugal because the malware only finishes the attack when the visitor matches that region. Standard sandbox detonation and URL review can miss it entirely, so a live phishing run can look harmless in the lab.
FortiGuard says Ousaban has been active against Spain and Portugal since May 2026. It uses phishing PDFs, server-side checks on language, time zone, and IP, blocks VPNs and sandboxes, then hides its payload inside an image via steganography before moving on to banking theft.
The practical risk is undercounted exposure. Teams that only trust outside-the-region analysis can miss infections until customer logins, fraud, or complaints show up.
2 sources covering this story
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
Fortinet says the May 2026 Ousaban campaign uses PDF lures, geofencing, and steganography to target Windows banking users.
Brazilian Banking Trojan Ousaban Targets Spain and Portugal
FortiGuard says the Brazilian banking trojan Ousaban is targeting Spain and Portugal via phishing
Part of the PlainSec briefing for 2026-07-01