← Back to Feed

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

July 1, 2026 · Fortinet Threat Research · Severity: MEDIUM

FortiGuard Labs has identified an ongoing Ousaban malware campaign specifically targeting organizations in Spain and Portugal. The attackers employ phishing emails containing malicious PDF attachments, which use steganography to conceal malicious code. Once executed, the malware establishes communication with command-and-control (C2) servers using evasive techniques to avoid detection. The campaign leverages social engineering tactics to trick victims into opening the PDFs, which then deploy the Ousaban payload. The campaign primarily affects businesses and individuals in the Iberian Peninsula, with a focus on sectors like finance, healthcare, and government. The use of steganography and evasive C2 infrastructure makes detection and mitigation challenging for traditional security tools. This attack highlights the increasing sophistication of threat actors targeting specific regions and industries. Organizations in the affected areas are urged to enhance email security, educate employees about phishing risks, and implement advanced threat detection mechanisms to counter such threats.

FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing PDFs, steganography, and evasive C2.

      

Key Takeaways

  • Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula — FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing...
  • Phishing awareness training and email filtering remain essential first-line defenses.
  • Active attack campaigns require immediate defensive measures including network segmentation and monitoring.
  • Regular security awareness training and layered defenses remain the foundation of any effective cybersecurity program.
☕ Buy a Coffee