Ousaban Resurfaces in Iberia, Hiding Bank-Stealer Payloads Inside Images
A Brazilian trojan pivots to Spanish and Portuguese banking customers, using geofenced PDF lures and steganography to bury its real payload.

Key points
- Fortinet's FortiGuard Labs identified a May 2026 campaign delivering Ousaban to Windows users banking in Spain and Portugal.
- A geofenced loader blocks execution outside the target region, slowing sandbox analysis.
- The real payload is hidden inside an image file using steganography and decoded in memory.
- Ousaban overlays fake login windows on real bank sessions to harvest passwords and OTPs.
- Phishing-resistant factors such as WebAuthn passkeys would defeat the overlay; static OTPs would not.
Ousaban is back, and it has learned some new tricks.
Fortinet's FortiGuard Labs flagged a fresh campaign in May 2026 aimed at Windows users banking in Spain and Portugal. The delivery chain, and the care taken to filter out anyone who isn't Iberian, is what makes this run worth watching.
How does the attack reach victims?
The lure is a phishing email carrying a PDF that presents itself as corrupted. Curious users click through to "fix" the document and end up fetching a downloader from an attacker-controlled host. Before anything else fires, the loader checks the victim's geolocation: if the IP resolves outside Spain or Portugal, execution stops. That geofence keeps sandboxes in the US and elsewhere from seeing the real second stage, a common but effective way to slow reverse engineering.
For victims inside the target region, the loader pulls what looks like an ordinary image file. The actual payload is hidden inside using steganography (concealing data within an innocuous carrier file), then decoded in memory. We covered a related steganography technique on 29 June 2026 when Microsoft pulled 119 Edge extensions tied to the StegoAd campaign; the method of hiding code in image files is clearly finding renewed appetite.
Once resident, Ousaban watches for browser sessions against Iberian banks and overlays fake login windows on the real ones to harvest credentials. Some variants also run screen captures and keylogging.
This is credential theft, full stop. Not a session-hijack story, not a token-replay story. Ousaban wants your password and, where a bank still relies on static second factors, your OTP too.
Should you worry about MFA here?
Partly. SMS OTPs and TOTP codes typed into an overlay window are trivially relayed by the operator in real time. Phishing-resistant factors, specifically WebAuthn under FIDO2/CTAP2 or platform passkeys, would defeat the overlay entirely: the browser will not release an assertion to a process sitting on top of the page. European banks are moving that direction under PSD2's strong customer authentication rules, but overlay-friendly OTP flows remain widespread. That gap is where Ousaban lives.
Also worth noting: Spain appeared in our Grandoreiro coverage on 28 May, and that campaign similarly relied on mundane lures hiding capable payloads. Two Iberian-focused banking trojan campaigns inside a month suggests the region is being treated as a productive target, not an opportunistic one.
What should defenders and end users actually do?
For SOC teams: block execution of unsigned binaries dropped by PDF readers; alert on processes that fetch image files and immediately allocate large executable memory regions, which is classic stego-decode behaviour; and prioritise endpoint telemetry that surfaces browser process injection over any single IOC list, since the operators rotate infrastructure aggressively.
For end users, the advice is duller than the malware deserves. Don't open PDFs that claim to be broken. Enroll a passkey or hardware security key if your bank offers one. SMS-only MFA is a product decision worth complaining about.
Ousaban has been active since roughly 2018. That it's still profitable in 2026 says more about banking authentication than about the malware.



