Malware Ousaban banking trojan targets Spain and Portugal with new stealth techniques July 1, 2026 Share By SC Staff (Adobe Stock Images) A Brazilian banking trojan known as Ousaban is actively targeting Windows users in Spain and Portugal, according to a report by Fortinet's FortiGuard Labs. This malware employs sophisticated techniques to evade detection and steal banking credentials, The Hacker News reports. The Ousaban campaign begins with a phishing PDF disguised as a corrupted file, prompting users to click an "Update" button. This action leads to a malicious webpage that screens visitors based on IP address, language, and time zone, blocking those outside Spain or Portugal. The malware's payload is hidden within an image file using steganography, a technique that conceals data within other files. Once executed on a Windows system, Ousaban waits to capture screenshots, keystrokes, and manipulate clipboard data when users access targeted banking websites. It monitors over two dozen banks in the region, including major institutions like Banco Santander and BBVA. The trojan's command and control infrastructure is designed to be elusive, with daily changing server addresses. This campaign is part of a broader trend of Brazilian banking trojans, such as Grandoreiro and Guildma, that have evolved to target Iberian markets with advanced evasion tactics. Source: The Hacker News SC Staff Related Malware ScreenConnect abused to deploy AsyncRAT in widespread campaign SC Staff July 1, 2026 This activity is part of a large, multi-language campaign that distributes malicious installer archives hosted on spoofed websites, according to a recent report by The Hacker News. Malware RustDuck botnet rapidly evolves with migration to Rust SC Staff July 1, 2026 RustDuck targets a variety of IoT devices, including routers, cameras, and Android set-top boxes, as well as exposed servers running software like ThinkPHP and Jenkins. Malware Attack exploiting SimpleHelp vulnerability deploys novel loader, infostealer Laura French June 30, 2026 The TaskWeaver loader delivers Djinn Stealer, which targets dev credentials and AI tokens. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds