← All stories
● Covered by 1 source · 1 reportMedium impact

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Targets banking users in Spain and Portugal
  • Uses phishing PDFs to initiate attacks
  • Steals banking login credentials and account access

Overview of Ousaban Trojan

The Ousaban banking trojan has been identified by Fortinet’s FortiGuard Labs as targeting Windows users specifically banking in Spain and Portugal. It operates by misleading users into opening a phishing PDF that appears as a corrupted file.

Attack Vector

The attack commences with a PDF file prompting users to click a button for updates. This action either redirects to a malicious webpage or executes hidden JavaScript to facilitate the download of the trojan.

The trojan masquerades its payload within an image, which deceives security measures and delivers a ZIP file containing the malicious software.

Functionality of Ousaban

Once installed, Ousaban monitors user's online banking activity, capturing keystrokes, screenshots, and modifying clipboard contents. It particularly targets over two dozen banks including major institutions like Banco Santander and BBVA.

With the capability to interact during live banking sessions, Ousaban can effectively hijack accounts.

Evasion Techniques

Ousaban employs various evasion techniques to establish its presence. Initially, it checked the victim's location using IP, language, and other criteria before triggering its payload.

In its latest variant, such checks occur on the command server, keeping the screening rules hidden and barring users located outside the Iberian region.

Ongoing Threat and Mitigation

The command server for Ousaban is continuously changing to evade detection, making it difficult to track. Past versions of the malware have hidden configurations using services like Google Docs. Users are advised to remain vigilant against such phishing attempts and use strong security practices when banking online.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The Ousaban banking trojan is targeting Windows users in Spain and Portugal through phishing PDFs designed to look like corrupted files. This malware can capture sensitive information during online banking sessions, posing a significant threat to users' accounts.