CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 45

As cited

Copy frozen at (site build).

threat intel

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

Fortinet researchers identified a campaign in May 2026 targeting banking users in Spain and Portugal with Ousaban, a Brazilian banking trojan distributed through phishing emails containing fake PDF files. The malware verifies the victim's geographic location and conceals its payload within image files to steal banking credentials.

Why it matters: This trojan targets banking credentials through geofenced phishing, requiring immediate awareness among Spanish and Portuguese banking users to avoid credential theft.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

Fortinet researchers identified a campaign in May 2026 targeting banking users in Spain and Portugal with Ousaban, a Brazilian banking trojan distributed through phishing emails containing fake PDF files. The malware verifies the victim's geographic location and conceals its payload within image files to steal banking credentials.

Why it matters: This trojan targets banking credentials through geofenced phishing, requiring immediate awareness among Spanish and Portuguese banking users to avoid credential theft.

VendorsMicrosoftFortinet
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary