FortiGuard Labs identified a May 2026 campaign targeting users in Spain and Portugal with the banking Trojan Ousaban, delivered through phishing PDFs, malicious webpages, VBS files, and steganographic images. The attack uses geofencing, server-side environment checks, daily-changing DDNS hostnames, and encrypted C2 traffic to hide its activity and steal banking-related information. #Ousaban #FortiGuardLabs #Spain #Portugal #Pastebin
Keypoints
- FortiGuard Labs observed a campaign in May 2026 targeting users in Spain and Portugal with the banking Trojan Ousaban.
- The initial lure is a phishing PDF disguised as a corrupted document that prompts the victim to âupdateâ it via a malicious link.
- The attack chain uses a malicious webpage, a VBS downloader, a steganographic image, a ZIP archive, and a final EXE payload.
- The webpage performs geofencing and environment checks to restrict delivery to intended victims and block automated analysis tools.
- Ousaban establishes persistence through a Run registry value and uses encrypted strings to target specific banking services.
- The malware resolves its C2 through daily-changing DDNS hostnames and encrypts most server traffic with a custom algorithm.
- Earlier late-2025 variants also used ClickFix-style and PDF-based initial access leading to an MSI installer and Rust-based downloader.
MITRE Techniques
- [T1566.003 ] Phishing: Spearphishing Link â The phishing PDF directs victims to a malicious webpage that begins the infection chain (âAtualizar button links to a malicious webpageâ).
- [T1204.002 ] User Execution: Malicious File â The victim is tricked into opening a disguised PDF and following the update prompt to continue the attack (âdisguised as a corrupted fileâ and prompts the victim to update it).
- [T1027 ] Obfuscated Files or Information â The PDF JavaScript is hex-escaped and the malware uses encrypted strings and encoded traffic to hinder detection (âThis JavaScript code is hex-escaped to evade detectionâ and âMost of the traffic⌠is encryptedâ).
- [T1497.001 ] Virtualization/Sandbox Evasion: System Checks â The webpage checks language, time zone, IP, screen resolution, browser rendering, and fonts to block sandboxes and crawlers (âidentify and block automated tools, such as sandboxes and crawlersâ).
- [T1036 ] Masquerading â The malicious webpage imitates legitimate tax documents and installers, and the PDF pretends to be corrupted (âmasquerades as a legitimate source of tax documentsâ and âdisguised as a corrupted fileâ).
- [T1105 ] Ingress Tool Transfer â The attack downloads VBS, ZIP, image, and EXE payloads from the malicious infrastructure (âdownloads a VBS fileâ and âretrieves the Ousaban payloadâ).
- [T1027.003 ] Steganography â The VBS downloads a steganographic image that hides a ZIP file containing the payload (âdownloads a steganographic imageâ and âextracts a ZIP file from the imageâ).
- [T1071.001 ] Application Layer Protocol: Web Protocols â The malware uses webpages, Pastebin, Google Automated Queries, and browser-based requests to retrieve environment and C2-related data (âaccesses the same webpageâ and âlooks up a hostnameâ).
- [T1090.001 ] Proxy: Internal Proxy â The anti-analysis code blocks VPN-linked IPs by searching for VPN-related keywords in organization info (âblocks IP addresses linked to VPNsâ).
- [T1057 ] Process Discovery â The environment checks inspect running/browser behavior and device characteristics to determine whether the user is automated or real (âbrowser rendering, and font enumerationâ).
- [T1016 ] System Network Configuration Discovery â The webpage and malware verify language, time zone, and IP details to identify the victimâs location (âverifies language, time zone, and IP detailsâ).
- [T1497 ] Virtualization/Sandbox Evasion â The malware detects restricted environments and serves an error or fake file when checks fail (âif the user doesnât pass the environment checkâ).
- [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder â Ousaban creates a Run key value for persistence (âcreates a registry value named Financeiro in the CurrentVersion/Run registry keyâ).
- [T1005 ] Data from Local System â The malware collects victim environment data and browser/device information before deciding delivery (âEnvironmental information is sent to the threat actorâ).
- [T1568.002 ] Dynamic Resolution: Domain Generation Algorithms â The C2 hostname changes daily based on date-derived MD5 data (âhostnames change dailyâ and âsubdomains consist of⌠the first eight characters of an MD5 hashâ).
- [T1033 ] System Owner/User Discovery â The malware gathers user/system details to profile the victim and tailor its response (âCollect user informationâ).
- [T1056.001 ] Input Capture: Keylogging â The C2 command list includes keylogger functionality during remote-control setup (âimplementing a keyloggerâ).
- [T1115 ] Clipboard Data â The malware supports clipboard injection as part of victim interaction (âperforming clipboard injectionâ).
- [T1021 ] Remote Services â The malware enables remote control capabilities over the victim machine (âStart screenshot capture and remote control capabilityâ).
Indicators of Compromise
- [Domains ] malicious infrastructure and DDNS-related hosts â faturanova[.]xyz, facture-in[.]pages[.]dev, facture-arsys[.]duckdns[.]org, and 2 more domains
- [IP addresses ] C2 and related infrastructure â 213[.]159[.]64[.]191, 162[.]33[.]179[.]46, and 2 more IPs
- [PDF hashes ] phishing PDF samples â 6bc2e11b0917f47d0557288c4f0cb20bd7589185943b989a969fdc6d3704ee73540ee1936e61d2344b5ebc93485589a351ec2f113a9b4940ae16f3baa4807392e2f0c2d4c1552cd81fa012043e4a5ac832582b639b7b6b7eccc0c4802d7a8ad89d07a83cf89685651ea8992047ae694c24f6ddef193044357debd15ce07a64fe4c9fdc2823da505ef339d43c6ad38499b7e3447736733e42b5ab6b1afcfd42aa5e06af187b45476ade0d953e834fced6197d0a33ac60c2575877660e26ab15e8
- [HTML hashes ] malicious webpage sample â 65c1a998bac48e02b52b1c850cd500e9fb87521e21755c3a4a491243f5f9a7009e81ade09cc18f0fc09d73e72d2e0bffad02f52fdcc26553e473cee8cabc15671e77992666acbbfa0d01fcefa9cc8fbdac291e0681b35745be27c6dfb159a375fadbb8061715128bebecf7bc59132b6bb04fe8cc39b965aa5b8722dffe28d7e7
- [VBS hashes ] downloader script sample â 5a2ed557c357ba8f96f2d55a8a00695987806b5df766cd1dfdab0cbed111774a19ac18a50abb48dc0ea9524850acfaec49359e6b3bcc67c6193c2d56da812c7148723a33bab89f174750576f9a62da35b3b9e5ac31a5a8f1ce9859a1b35bf8b8
- [MSI hashes ] installer sample from late-2025 campaign â 21b24f7ee1f6bdbbb670f0394d66009ee0daa8ced57048298da715e88f7a7cddd4eb4ff02df659fdeec17d36b77084627469623bb3c7d16383d257404b52d1c3
- [EXE hashes ] final payload sample â ffb9eb47cc0cb2f43e04a10dc84df13d04bca1ebacbe47fad0b669728de2f59c18fd38988d58dd930f5992d448cc09a9400c1eafba76b820b9a83239ac48cf4e4ca2c863d740bb7022776dccabd8ae34bb9998768928042d76ebcf08984eefcb5837e47198a20877e1b04b270c36d9194206ee38d4f32fe3151b3c3b396c4f0de6e78eb2e9bd41a4bc62f7ad54d095ea9813864bebe37172ae30a1afa631fe14