A highly targeted phishing campaign spreading the Ousaban banking trojan to users in Spain and Portugal.
Historically active in Brazil, this updated malware uses advanced geofencing, steganography, and daily-changing command-and-control domains to evade detection.
The attack begins with a deceptive PDF and ultimately grants attackers full remote control over the victim’s machine, allowing them to steal sensitive financial data.
Ousaban Geofenced Phishing Campaign
The attack sequence starts with a phishing PDF disguised as a corrupted file. It prompts the victim with an “Atualizar” (Update) button and contains hex-escaped JavaScript that stealthily redirects the user to a malicious webpage.
This webpage acts as a strict gatekeeper, masquerading as a legitimate source for tax documents or system installers while performing rigorous environmental checks.
To ensure only the intended targets receive the malware, the server verifies the user’s IP address, time zone, and language settings.

It specifically looks for connections originating from Spain or Portugal. The code actively blocks automated analysis tools, such as sandboxes and crawlers, by checking screen resolution and browser rendering capabilities, and it restricts IP addresses associated with VPNs.
If a user fails this environment check, they receive a decoy PDF displaying an “Access denied” message in Spanish.
When a target passes the verification, the server delivers a VBScript file. This script triggers the download of a steganographic image that appears to be a standard PDF icon.
Hidden within this image is a ZIP archive containing the final Ousaban executable payload. The script extracts the payload to the victim’s temporary folder, executes it, and immediately deletes the original files to minimize its forensic footprint.
According to Fortinet research, Ousaban establishes persistence by creating a registry value named “Financeiro” and dropping a timestamped configuration file.

The malware specifically monitors web browser activity for a predefined list of targeted banking services. To protect its internal strings, Ousaban utilizes a custom encryption algorithm common among Latin American banking trojans.
This process involves a randomized base offset and a specific XOR sequence, ensuring that identical plaintexts produce different ciphertexts to complicate reverse engineering.
If a mathematical calculation is needed to adjust the offset, the algorithm adds 0xFF0xFF0xFF to the difference when the XOR result is smaller than the base offset.
Indicators of Compromise
| Indicator Type | Value | Context / Description |
|---|---|---|
| Domain | faturanova[.]xyz | Associated C2 / malicious domain |
| Domain | facture-in[.]pages[.]dev | Associated C2 / malicious domain |
| Domain | facture-arsys[.]duckdns[.]org | Associated C2 / malicious domain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.