cyberthreatintel (1)

31189739096?profile=RESIZE_400xIn May 2026, FortiGuard Labs identified an attack targeting users in Spain and Portugal involving the banking Trojan Ousaban.  This malware has been active in Brazil and is spread through an MSI downloader.  The malicious payload is a DLL that is loaded via DLL sideloading or process injection.

In this campaign, the threat actor primarily targets users in Spain and Portugal. Figure 1 shows how the attack unfolds.  The phishing PDF tricks victims into visiting a malicious webpage that scans the u