The images in this article were generated with artificial intelligence. How we publish
The reappearance of the Ousaban banking trojan - also known as Javali - in campaigns aimed at Windows users in Spain and Portugal confirms that the old financial crime playbook remains effective when combined with modern stealth techniques. Fortinet detected the campaign in May 2026 and describes a compact infection chain: a PDF that pretends to be corrupt, a geographical check that separates real noise victims and a malicious file camouflaged into a PDF icon-looking image. The goal has not changed: to steal bank credentials and to kidnap live sessions. For the end user this means that a simple bill or unexpected tax notice may be enough to lose access to an account if the guard is lowered.
Operational sophistication is in the details: the campaign applies advanced geofencing and screening to show malware only to visitors in Spain or Portugal, and has moved much of that logic to the attacker's server so that the exact rules are hidden. He also uses steganography to hide a ZIP within an image and a routine that erases prints after running the Trojan. These techniques reduce the likelihood of automatic sandbox detection and static indicator capture. The technical consequence is clear: blocking a known domain may not be enough because the control infrastructure changes frequently and some indicators published by analysts may be decoy addresses.

Ousaban operates in patient mode: it is installed as persistence in Windows - adding a log entry called Finanbeiro- and wait for the user to visit one of the banks on his surveillance list (more than two dozen between Spain and Portugal, including large names such as Santander, BBVA or CaixaBank). When you detect the load of a bank website you can capture pants, record pulsations, manipulate the clipboard, display false messages and offer remote control to the attacker. With this set of capabilities it is possible to kidnap an online banking session in real time and approve transfers.
This case fits a well-known trend: families of Brazilian Trojans - the so-called "Tetrade" that includes Grandoreiro, Guildma and Melcoz - have migrated and adapted techniques among them. The resistance and recycling of malicious infrastructure became evident when Grandoreiro returned after a coordinated operation in 2024. Kaspersky and other laboratories have been documenting this movement and the exchange of code between families for years; knowing these relationships helps to anticipate future tactics and prioritize defenses.
From a defensive point of view there are several practical implications. First, detection only by detonating links in link doors may fail: the server-side screening returns a "denied access" page to automated environments. Second, the daily rotation of command and control addresses complicates long-term blockages. Third, the use of public services (Pastebin, Google Docs) to hide configurations requires monitoring behaviors and not just known domains. Strategies should therefore combine proactive mail filtering, behavior-based detection and endpoints telemetry in real environments.
For users and companies the first line of defense is the prevention in email: to treat as suspects the PDFs that claim to be corrupt, the unexpected invoice attachments and any instruction that asks to press a "Update" button or stick commands on a console to "fix an error." It is also critical to educate bank customers not to stick commands or run files for indications on doubtful pages. Basic hygiene - not opening unexpected attachments, validating by another way the warnings and keeping Windows and antivirus up-to-date - remains the most effective measure.
For security equipment and service providers managed, it is appropriate to adapt sandboxes and artificial response to reproduce real victim conditions in Spain and Portugal (time zone, language, screen size, installed sources); in addition, rules that detect indicators of persistence such as the registration key should be implemented. Finanbeiro or the presence of files on routes such as C:\\ SysMain _ 5874288. Fortinet, who detected the campaign, publishes analysis and signatures on his research blog; reviewing and applying those IOCs and signatures is a practical step for operational defence: Fortinet Threat Research.

Banks and financial institutions should take advantage of complementary controls: deploy robust multifactor authentication (preferably based on hardware or token applications), off-site transaction signing measures and fraud detection systems that monitor device changes or anomalous behaviour when approving operations. A multi-layer control scheme increases friction for the attacker and reduces the probability of successful fraud even if malware steals credentials.
At the level of legal and cooperation response, the daily dispersion of infrastructure and the use of public services to hide it make blocking orders and take-over difficult. This is why collaboration between banks, cybersecurity companies and security forces is essential to share relevant patterns of conduct and IOCs, and to coordinate actions that interrupt distribution chains. The experience of previous takedowns shows that the interruption can be temporary if operators' ability to recycle domains and services is not attacked.
In short: Ousaban does not invent new capabilities, but it does again demonstrate that the combination of precise social engineering, geographical screening and effective concealment techniques remains very dangerous. Users in Spain and Portugal should assume that tax documents or unexpected invoices can be traps and act with caution; defenders should expand their approach beyond domain blocking and strengthen behaviour-based detection and coordinated response. For practical guidelines on prevention of phishing and improvement of digital hygiene, the response and awareness documentation can be consulted in reference agencies and laboratories, such as CISA and the technical blogs of the security providers mentioned above.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...