A sophisticated campaign involving the Brazilian banking trojan, Ousaban, has been identified targeting Windows users predominantly in Spain and Portugal. Fortinet’s FortiGuard Labs recently brought this evolving threat to light, detailing the advanced tactics employed by the malware to evade detection and hijack banking sessions. The campaign, which was observed intensifying in May 2024, underscores the persistent and adaptable nature of cybercriminal operations originating from Brazil and expanding into the Iberian Peninsula.
The Evolving Threat Landscape of Banking Trojans
The emergence of Ousaban, also known as Javali, is not an isolated incident but rather a continuation of a long-standing trend in cybercrime. Brazilian banking trojans have historically been notorious for their ingenuity and aggressive tactics, initially focusing on domestic targets before extending their reach globally. Cybersecurity firm Kaspersky previously categorized several prominent families of these threats, including Grandoreiro, Guildma, Melcoz, and Ousaban, under the collective term "Tetrade." These groups are characterized by their shared codebases, collaborative development, and a consistent playbook of sophisticated social engineering and technical evasion techniques. Their expansion into Spain and Portugal is often attributed to linguistic and cultural ties, which allow for more convincing phishing lures, as well as the robust financial sectors in these European nations.
Banking Trojans are a particularly insidious form of malware designed to steal sensitive financial information, such as login credentials, credit card details, and personal identification numbers (PINs). Once a system is compromised, these Trojans typically monitor user activity, specifically looking for interactions with banking websites. Upon detecting a target bank’s online portal, they can then deploy a range of tactics, from passive data exfiltration to active manipulation of the user’s session, ultimately aiming to gain unauthorized access to accounts and initiate fraudulent transactions. The financial implications for victims, ranging from individual account holders to the banks themselves, can be substantial, often involving significant monetary losses and reputational damage.
A Detailed Look at Ousaban’s Attack Chain
The current Ousaban campaign initiates its assault through a meticulously crafted phishing scheme. The primary vector is a seemingly innocuous PDF document, cleverly disguised as a corrupted file. This document presents a prompt to the victim, urging them to press an "Atualizar" (Update) button, ostensibly to repair the corrupted file. Unbeknownst to the user, clicking this button, or even allowing hidden JavaScript embedded within the PDF to execute automatically, redirects them to a malicious webpage. This page is designed to mimic a legitimate tax-document or installer portal, adding a layer of credibility to the deception.

A critical component of Ousaban’s strategy is its sophisticated visitor screening mechanism, often referred to as "geofencing" and anti-analysis. Earlier iterations of the malware performed these checks directly within the victim’s browser, scrutinizing various parameters such as the visitor’s IP address, preferred language settings, and local time zone. Furthermore, these older versions were adept at identifying and blocking traffic originating from Virtual Private Networks (VPNs), a common tool used by security researchers to analyze malware in a controlled environment. They also filtered out automated security tools by examining granular details like screen size and installed fonts, which can often betray a virtualized or sandbox environment. The latest variant of Ousaban has elevated this evasion tactic by moving the screening process to the operator’s server. This server-side validation ensures that the exact rules and parameters used for filtering remain concealed from potential investigators, making it significantly harder to reverse-engineer their detection logic. If a visitor fails to meet the criteria – specifically, if they are not located in Spain or Portugal – they are simply presented with a benign Spanish "access denied" notice, effectively preventing the malware from being delivered to unintended targets or security analysts outside the intended geographic scope.
Upon successfully clearing the initial screening checks, the download of the malicious payload commences. The infection chain employs a clever technique known as steganography, where the actual malware is hidden within an apparently harmless image file. This image, typically designed to resemble a common PDF icon, conceals a compressed ZIP archive. A script then downloads this image, extracts the Ousaban trojan from the embedded ZIP file, and executes it. To minimize forensic traces and complicate detection, the script subsequently deletes the original image file, the ZIP archive, and itself, leaving very little behind. Once Ousaban is running on the Windows PC, it establishes persistence by adding a registry entry named "Financeiro" (Portuguese for "finance"). This entry ensures that the malware automatically launches every time the Windows operating system starts, granting it continuous access to the compromised system.
Evasive Command and Control Infrastructure
One of the hallmarks of Ousaban’s sophistication lies in its highly evasive Command and Control (C2) infrastructure. The C2 server, which acts as the central hub for the attackers to control the compromised systems and exfiltrate stolen data, is deliberately made difficult to locate. Fortinet’s analysis reveals that the malware initially accesses a Pastebin link, which deceptively points to a decoy server address. This serves as a false lead for researchers attempting to trace the C2 infrastructure. The true C2 server, however, is dynamic and changes daily. Ousaban achieves this by first reading the current date from a legitimate Google page. It then uses this date, combined with a fixed, secret string, to construct a unique web address for that specific day. This dynamic C2 mechanism ensures that blocking yesterday’s address does little to mitigate the threat, as the attackers can simply move to a new address the following day. This practice of hiding critical operational details within legitimate web services is a recurring theme for Ousaban; earlier campaigns, for instance, were observed stashing their configuration files within Google Docs. Such tactics highlight the attackers’ commitment to operational security and their continuous efforts to circumvent traditional detection and blocking methods.
Ousaban’s Operational Capabilities and Impact
Once Ousaban successfully infiltrates a Windows system and establishes persistence, it patiently waits for the user to access a banking website. The malware is specifically configured to monitor for interactions with over two dozen financial institutions across Spain and Portugal. Prominent targets include major banks such as Banco Santander, BBVA, CaixaBank, Bankinter, and Caixa Geral de Depósitos, among others. When a user navigates to one of these monitored banking sites, Ousaban springs into action, deploying a comprehensive suite of tools designed to facilitate account takeover.
Its capabilities include:

- Keystroke Logging: Capturing every keystroke made by the victim, including login credentials, passwords, and sensitive financial data.
- Screenshot Capture: Taking periodic screenshots of the user’s active desktop, particularly when banking applications or websites are open, providing attackers with visual context of the victim’s activities.
- Clipboard Tampering: Manipulating the content of the system clipboard, potentially altering copied bank account numbers or cryptocurrency wallet addresses during transactions.
- Displaying Fake Messages: Injecting fraudulent pop-up messages or overlays onto legitimate banking pages, tricking users into revealing additional information or authorizing unauthorized transactions.
- Remote Control: Granting the attacker remote access and control over the compromised machine, allowing them to directly manipulate the banking session, initiate transfers, or change account settings.
Collectively, these sophisticated tools enable the attackers to hijack live banking sessions, bypass multi-factor authentication in some cases, and effectively take over bank accounts. The potential financial losses from such a widespread and targeted campaign are significant, impacting both individual account holders through direct theft and financial institutions through fraud remediation costs and reputational damage.
Broader Implications and Precedents
The tactics employed by Ousaban are not entirely novel but represent an evolution and refinement of methods long associated with Brazilian banking trojans. The "Tetrade" families, including Ousaban, have a history of sharing code and adapting successful techniques from one another. For instance, Ousaban’s custom string encryption scheme is reportedly identical to that used by another family, Casbaneiro, illustrating the collaborative and iterative nature of these criminal enterprises.
The resilience of these groups is perhaps best exemplified by Grandoreiro, another prominent member of the "Tetrade." In January 2024, Grandoreiro was the subject of a major Interpol-coordinated takedown operation, "Operation Crypton," which aimed to dismantle its infrastructure and apprehend its operators. Despite this significant law enforcement action, Grandoreiro demonstrated remarkable tenacity, resurfacing within months with renewed campaigns. Its loaders continued to rely on a similar playbook to Ousaban, leveraging PDF-looking lures and country-specific checks to deliver its payload. Reports from May 2024 indicate that Grandoreiro remains active, specifically targeting Portuguese banks, further underscoring the persistent threat to the Iberian Peninsula.
Fortinet’s research also connects the infrastructure used in the current Ousaban campaign to earlier activities in late 2025. These earlier campaigns utilized alternative entry points, such as the "ClickFix" scam. In this social engineering tactic, victims are tricked into believing they are fixing a system error by pasting a malicious command themselves, inadvertently executing the initial stages of the malware infection. This diversification of entry points highlights the adaptability of the threat actors and their continuous search for new ways to compromise targets. The overall trend points to a well-resourced and highly organized cybercrime ecosystem that constantly innovates to bypass security measures and exploit human vulnerabilities.
Mitigation and Prevention Strategies
Protecting against sophisticated threats like Ousaban requires a multi-layered approach involving both individual vigilance and robust organizational security measures.

For Individuals:
- Exercise Extreme Caution with Emails and Attachments: Treat any PDF or email that claims a file is corrupted and prompts you to press an "Update" button with extreme suspicion. The same applies to unexpected invoices, tax documents, or other attachments, especially if they are unsolicited or from unfamiliar senders. Cybercriminals often exploit a sense of urgency or curiosity.
- Never Paste Commands Blindly: Be wary of any prompts that instruct you to paste commands into a command line interface (e.g., PowerShell, Command Prompt) to "fix" an error. This is a common social engineering tactic to trick users into self-infecting their systems.
- Enable Multi-Factor Authentication (MFA): Where available, activate MFA on all banking and critical online accounts. Even if credentials are stolen, MFA adds a crucial layer of security, making it significantly harder for attackers to gain unauthorized access.
- Keep Software Updated: Regularly update your operating system, web browsers, and all installed applications. Software updates often include patches for newly discovered security vulnerabilities that malware exploits.
- Use Reputable Antivirus/Antimalware Software: Ensure your Windows PC has a robust and up-to-date antivirus solution. While Ousaban employs evasion tactics, a good security suite can still detect and block many known threats.
For Organizations and IT Professionals:
- Robust Email Security Gateways: Implement advanced email security solutions that can effectively detect and quarantine phishing emails, malicious attachments, and suspicious links before they reach end-users.
- Endpoint Detection and Response (EDR): Deploy EDR solutions to monitor endpoints for suspicious activity, identify malware behavior, and enable rapid response to incidents.
- Network Monitoring: Continuously monitor network traffic for anomalous patterns, C2 communications, and data exfiltration attempts.
- Security Awareness Training: Conduct regular and comprehensive security awareness training for employees, emphasizing the dangers of phishing, social engineering tactics, and the importance of verifying unexpected requests.
- Timely Patch Management: Maintain a rigorous patch management program to ensure all systems and software are up-to-date, minimizing the attack surface.
- Leverage Threat Intelligence: Integrate threat intelligence feeds, such as those provided by Fortinet’s FortiGuard Labs, into security operations to stay informed about emerging threats and implement proactive defensive measures. Specifically, defenders should monitor for the "Financeiro" registry Run key and watch for files dropped to
C:SysMain_5874288. Fortinet also provides specific domains, IP addresses, and file hashes that should be blocked at the network perimeter. - Advanced Sandbox Analysis: Recognize that basic automated sandboxes may be bypassed by Ousaban’s geofencing. More advanced, context-aware detonation environments are necessary to fully analyze such evasive threats.
Conclusion
The Ousaban banking trojan represents a significant and persistent threat to Windows users in Spain and Portugal. Its sophisticated combination of social engineering, advanced evasion techniques including server-side geofencing and dynamic C2 infrastructure, and steganographic payload delivery showcases the evolving ingenuity of cybercriminal groups. While the core trojan itself may be established, the continuous refinement of its "wrapper" tactics ensures its efficacy against conventional security measures. The history of Brazilian banking trojans, particularly the rapid resurgence of Grandoreiro after a major takedown, serves as a stark reminder of the resilience and adaptability of these threat actors. As the digital landscape continues to evolve, individuals and organizations must remain highly vigilant, adopting comprehensive security strategies and staying informed about the latest cyber threats to protect their financial assets and sensitive data from these relentless campaigns.
