This campaign can look quiet from outside Spain and Portugal because the malware only finishes the attack when the visitor matches that region. Standard sandbox detonation and URL review can miss it entirely, so a live phishing run can look harmless in the lab.
FortiGuard says Ousaban has been active against Spain and Portugal since May 2026. It uses phishing PDFs, server-side checks on language, time zone, and IP, blocks VPNs and sandboxes, then hides its payload inside an image via steganography before moving on to banking theft.
The practical risk is undercounted exposure. Teams that only trust outside-the-region analysis can miss infections until customer logins, fraud, or complaints show up.