Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

FortiGuard Labs identified a May 2026 campaign targeting users in Spain and Portugal with the banking Trojan Ousaban, delivered through phishing PDFs, malicious webpages, VBS files, and steganographic images. The attack uses geofencing, server-side environment checks, daily-changing DDNS hostnames, and encrypted C2 traffic to hide its activity and steal banking-related information. #Ousaban #FortiGuardLabs #Spain #Portugal #Pastebin

Keypoints

  • FortiGuard Labs observed a campaign in May 2026 targeting users in Spain and Portugal with the banking Trojan Ousaban.
  • The initial lure is a phishing PDF disguised as a corrupted document that prompts the victim to “update” it via a malicious link.
  • The attack chain uses a malicious webpage, a VBS downloader, a steganographic image, a ZIP archive, and a final EXE payload.
  • The webpage performs geofencing and environment checks to restrict delivery to intended victims and block automated analysis tools.
  • Ousaban establishes persistence through a Run registry value and uses encrypted strings to target specific banking services.
  • The malware resolves its C2 through daily-changing DDNS hostnames and encrypts most server traffic with a custom algorithm.
  • Earlier late-2025 variants also used ClickFix-style and PDF-based initial access leading to an MSI installer and Rust-based downloader.

MITRE Techniques

  • [T1566.003 ] Phishing: Spearphishing Link – The phishing PDF directs victims to a malicious webpage that begins the infection chain (‘Atualizar button links to a malicious webpage’).
  • [T1204.002 ] User Execution: Malicious File – The victim is tricked into opening a disguised PDF and following the update prompt to continue the attack (‘disguised as a corrupted file’ and prompts the victim to update it).
  • [T1027 ] Obfuscated Files or Information – The PDF JavaScript is hex-escaped and the malware uses encrypted strings and encoded traffic to hinder detection (‘This JavaScript code is hex-escaped to evade detection’ and ‘Most of the traffic… is encrypted’).
  • [T1497.001 ] Virtualization/Sandbox Evasion: System Checks – The webpage checks language, time zone, IP, screen resolution, browser rendering, and fonts to block sandboxes and crawlers (‘identify and block automated tools, such as sandboxes and crawlers’).
  • [T1036 ] Masquerading – The malicious webpage imitates legitimate tax documents and installers, and the PDF pretends to be corrupted (‘masquerades as a legitimate source of tax documents’ and ‘disguised as a corrupted file’).
  • [T1105 ] Ingress Tool Transfer – The attack downloads VBS, ZIP, image, and EXE payloads from the malicious infrastructure (‘downloads a VBS file’ and ‘retrieves the Ousaban payload’).
  • [T1027.003 ] Steganography – The VBS downloads a steganographic image that hides a ZIP file containing the payload (‘downloads a steganographic image’ and ‘extracts a ZIP file from the image’).
  • [T1071.001 ] Application Layer Protocol: Web Protocols – The malware uses webpages, Pastebin, Google Automated Queries, and browser-based requests to retrieve environment and C2-related data (‘accesses the same webpage’ and ‘looks up a hostname’).
  • [T1090.001 ] Proxy: Internal Proxy – The anti-analysis code blocks VPN-linked IPs by searching for VPN-related keywords in organization info (‘blocks IP addresses linked to VPNs’).
  • [T1057 ] Process Discovery – The environment checks inspect running/browser behavior and device characteristics to determine whether the user is automated or real (‘browser rendering, and font enumeration’).
  • [T1016 ] System Network Configuration Discovery – The webpage and malware verify language, time zone, and IP details to identify the victim’s location (‘verifies language, time zone, and IP details’).
  • [T1497 ] Virtualization/Sandbox Evasion – The malware detects restricted environments and serves an error or fake file when checks fail (‘if the user doesn’t pass the environment check’).
  • [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – Ousaban creates a Run key value for persistence (‘creates a registry value named Financeiro in the CurrentVersion/Run registry key’).
  • [T1005 ] Data from Local System – The malware collects victim environment data and browser/device information before deciding delivery (‘Environmental information is sent to the threat actor’).
  • [T1568.002 ] Dynamic Resolution: Domain Generation Algorithms – The C2 hostname changes daily based on date-derived MD5 data (‘hostnames change daily’ and ‘subdomains consist of… the first eight characters of an MD5 hash’).
  • [T1033 ] System Owner/User Discovery – The malware gathers user/system details to profile the victim and tailor its response (‘Collect user information’).
  • [T1056.001 ] Input Capture: Keylogging – The C2 command list includes keylogger functionality during remote-control setup (‘implementing a keylogger’).
  • [T1115 ] Clipboard Data – The malware supports clipboard injection as part of victim interaction (‘performing clipboard injection’).
  • [T1021 ] Remote Services – The malware enables remote control capabilities over the victim machine (‘Start screenshot capture and remote control capability’).

Indicators of Compromise

  • [Domains ] malicious infrastructure and DDNS-related hosts – faturanova[.]xyz, facture-in[.]pages[.]dev, facture-arsys[.]duckdns[.]org, and 2 more domains
  • [IP addresses ] C2 and related infrastructure – 213[.]159[.]64[.]191, 162[.]33[.]179[.]46, and 2 more IPs
  • [PDF hashes ] phishing PDF samples – 6bc2e11b0917f47d0557288c4f0cb20bd7589185943b989a969fdc6d3704ee73540ee1936e61d2344b5ebc93485589a351ec2f113a9b4940ae16f3baa4807392e2f0c2d4c1552cd81fa012043e4a5ac832582b639b7b6b7eccc0c4802d7a8ad89d07a83cf89685651ea8992047ae694c24f6ddef193044357debd15ce07a64fe4c9fdc2823da505ef339d43c6ad38499b7e3447736733e42b5ab6b1afcfd42aa5e06af187b45476ade0d953e834fced6197d0a33ac60c2575877660e26ab15e8
  • [HTML hashes ] malicious webpage sample – 65c1a998bac48e02b52b1c850cd500e9fb87521e21755c3a4a491243f5f9a7009e81ade09cc18f0fc09d73e72d2e0bffad02f52fdcc26553e473cee8cabc15671e77992666acbbfa0d01fcefa9cc8fbdac291e0681b35745be27c6dfb159a375fadbb8061715128bebecf7bc59132b6bb04fe8cc39b965aa5b8722dffe28d7e7
  • [VBS hashes ] downloader script sample – 5a2ed557c357ba8f96f2d55a8a00695987806b5df766cd1dfdab0cbed111774a19ac18a50abb48dc0ea9524850acfaec49359e6b3bcc67c6193c2d56da812c7148723a33bab89f174750576f9a62da35b3b9e5ac31a5a8f1ce9859a1b35bf8b8
  • [MSI hashes ] installer sample from late-2025 campaign – 21b24f7ee1f6bdbbb670f0394d66009ee0daa8ced57048298da715e88f7a7cddd4eb4ff02df659fdeec17d36b77084627469623bb3c7d16383d257404b52d1c3
  • [EXE hashes ] final payload sample – ffb9eb47cc0cb2f43e04a10dc84df13d04bca1ebacbe47fad0b669728de2f59c18fd38988d58dd930f5992d448cc09a9400c1eafba76b820b9a83239ac48cf4e4ca2c863d740bb7022776dccabd8ae34bb9998768928042d76ebcf08984eefcb5837e47198a20877e1b04b270c36d9194206ee38d4f32fe3151b3c3b396c4f0de6e78eb2e9bd41a4bc62f7ad54d095ea9813864bebe37172ae30a1afa631fe14


Read more: https://feeds.fortinet.com/~/958831322/0/fortinet/blog/threat-research~Analysis-of-Ongoing-Ousaban-Attacks-Targeting-the-Iberian-Peninsula