← Back to Feed

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

July 1, 2026 · Fortinet Threat Research · Severity: MEDIUM

FortiGuard Labs has uncovered an ongoing Ousaban malware campaign specifically targeting organizations in Spain and Portugal. The attackers use phishing emails with malicious PDF attachments that employ steganography to hide malicious code within seemingly harmless images. Once executed, the malware establishes communication with command-and-control (C2) servers using evasive techniques to avoid detection. The campaign is geographically focused, with infrastructure and lures tailored to Iberian Peninsula victims. The Ousaban malware, previously linked to Brazilian threat actors, poses a significant risk to financial and corporate sectors in the targeted regions. Its use of steganography and evasion tactics makes detection challenging for traditional security tools. Organizations in Spain and Portugal should remain vigilant against phishing attempts and monitor for suspicious PDF attachments, particularly those urging urgent action or containing unexpected image files. The campaign highlights the continued evolution of regionalized threats leveraging social engineering and advanced obfuscation techniques.

FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing PDFs, steganography, and evasive C2.

      

Key Takeaways

  • FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing PDFs.
☕ Buy a Coffee