Ousaban Banking Trojan Targets Banking Users

Researchers Discover a New Banking Attack

Ousaban Banking Trojan is targeting online banking users in Spain and Portugal. Researchers recently discovered the campaign targeting Windows devices. Moreover, attackers use fake PDF files to deliver the malware. Therefore, banking customers in these countries face a higher security risk.

The malware focuses on stealing online banking credentials. However, it also allows attackers to control infected computers remotely. As a result, criminals can hijack active banking sessions. This attack increases the chance of financial fraud and account theft.

Fake PDF Files Start the Infection

The attack begins with a phishing PDF attachment. The document appears damaged and asks the user to click an Update button. However, the button opens a malicious website instead of repairing the file. Consequently, victims unknowingly start the infection process.

Some PDF files also contain hidden scripts. Therefore, they may automatically open the malicious website without user interaction. The website checks whether the visitor matches the intended target. If the visitor fails the checks, the attack stops immediately.

Attackers Focus on Specific Regions

Researchers found that attackers carefully screen every visitor. For example, they verify the user’s location before delivering the malware. They also reject users outside Spain and Portugal. Therefore, the campaign remains hidden from many security researchers.

The attackers moved these checks to their own servers. However, this change makes the filtering process harder to analyze. As a result, automated security tools may miss the real malware. This strategy helps attackers avoid early detection.

Hidden Malware Evades Detection

After passing the security checks, victims download a disguised image file. However, the image secretly contains a compressed malware package. The installation script extracts the hidden files and launches the malware. It then deletes temporary files to reduce evidence.

The malware also creates a startup entry on Windows. Therefore, it automatically launches after every system restart. This persistence helps attackers maintain long-term access. Consequently, victims may remain infected for extended periods.

Ousaban Banking Trojan Steals Sensitive Data

Once active, Ousaban Banking Trojan waits for users to visit online banking websites. It monitors many financial institutions across Spain and Portugal. Moreover, it records keystrokes, captures screenshots, and modifies clipboard content. Therefore, attackers can steal login credentials and financial information.

The malware also supports remote control features. As a result, attackers can interact with the victim’s computer during banking sessions. They may display fake messages to hide suspicious activity. Consequently, users may not notice unauthorized transactions.

Researchers explained that this banking malware has existed for several years. However, attackers continue improving its delivery methods. They now combine fake PDF documents, regional filtering, and hidden malware files. Therefore, the campaign becomes more difficult to detect.

The malware also changes its communication methods regularly. Moreover, it generates new server addresses every day. This technique helps attackers avoid traditional security blocks. As a result, defenders must continuously update their detection strategies.

How to Prevent Ousaban Banking Trojan Attacks

Users should avoid opening unexpected PDF attachments or clicking update prompts from unknown emails. Moreover, they should verify banking websites before entering login credentials and keep Windows security updates installed. Organizations can strengthen protection through continuous security monitoring and managed detection and response services that quickly identify suspicious activity. Regular security awareness training also helps employees recognize phishing attempts and avoid fake banking documents before malware can compromise their devices.

Sleep well, we got you covered.

Scroll to Top