Ousaban banking trojan targets Spain and Portugal with new stealth techniques

SCM feed for Latest
Actively Exploited

Overview

The Ousaban banking trojan is targeting users in Spain and Portugal through a new phishing campaign. This campaign begins with a deceptive PDF file that appears to be corrupted, luring users to click an 'Update' button. Once activated, the trojan can compromise personal banking information, posing significant risks to individuals' finances. This type of attack demonstrates a shift towards more stealthy methods, making it harder for users to recognize the threat. As phishing techniques continue to evolve, it's crucial for users to remain vigilant and skeptical of unexpected prompts, especially those urging software updates.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Banking credentials, personal financial information
  • Action Required: Users should avoid clicking on suspicious links or downloading unexpected attachments.
  • Timeline: Newly disclosed

Original Article Summary

The Ousaban campaign begins with a phishing PDF disguised as a corrupted file, prompting users to click an "Update" button.

Impact

Banking credentials, personal financial information

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Users should avoid clicking on suspicious links or downloading unexpected attachments. It's recommended to keep antivirus software updated and to educate users on recognizing phishing attempts.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Phishing, Update, Trojan.

Related Coverage

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

The Hacker News

This week's security updates reveal a series of vulnerabilities across various systems, including browsers, AI tools, and email services. Researchers discovered that many of these weaknesses stem from small permission gaps and inadequate security checks, which attackers can exploit. Notably, the article mentions the BlueHammer ransomware, which targets businesses by leveraging these types of vulnerabilities. This situation underscores the need for organizations to regularly assess their security measures and patch any identified weaknesses to prevent potential breaches. Overall, the findings serve as a reminder that even seemingly secure systems can harbor significant risks if not properly maintained.

Jul 2, 2026

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure

SecurityWeek

Hackers have begun exploiting a newly disclosed vulnerability known as CitrixBleed, targeting NetScaler appliances. This vulnerability allows attackers to access arbitrary memory content through HTTP responses, putting sensitive information at risk. The exploitation started almost immediately after the vulnerability was publicly disclosed, indicating a rapid response from malicious actors. Organizations using affected NetScaler devices need to be vigilant, as this could lead to significant data breaches or unauthorized access. It's crucial for companies to take immediate action to safeguard their systems and protect sensitive information from being compromised.

Jul 2, 2026

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

The Hacker News

A new malware called Umbrij, linked to the cyber group ToddyCat, is targeting corporate Gmail accounts by exploiting the Google API. According to Kaspersky's recent report, the malware allows attackers to gain stealthy access to email communications, raising significant concerns for businesses that rely on Gmail for their operations. This tactic of compromising access through APIs highlights potential vulnerabilities in how companies manage their email systems. As email remains a primary communication tool for organizations, the implications of such breaches could be severe, resulting in sensitive information leaks and potential financial losses. Companies using Gmail should enhance their security measures to safeguard against this type of attack.

Jul 2, 2026

Researcher Behind 'Exploitarium' Explains Release of Undisclosed Zero-Day Exploits

Infosecurity Magazine

A cybersecurity researcher has released over 30 proof-of-concept exploits without revealing the underlying vulnerabilities first. This action, known as 'Exploitarium,' raises significant concerns within the cybersecurity community as it could enable malicious actors to exploit these vulnerabilities before they are patched. The researcher argues that this approach can pressure vendors to address security flaws more quickly. However, this practice may also put many users and organizations at risk, as they might not be aware of the potential threats posed by these exploits. The implications of this release emphasize the ongoing tension between security research and responsible disclosure, highlighting the need for better communication between researchers and vendors.

Jul 2, 2026

FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks

SecurityWeek

Researchers have identified that credentials stolen from FortiGate firewalls are being misused in ransomware attacks linked to the INC and Lynx groups. This breach, known as the FortiBleed campaign, has compromised hundreds of thousands of firewall credentials, allowing attackers to launch targeted ransomware operations. This situation poses a significant risk, as organizations relying on FortiGate firewalls may find themselves vulnerable to further exploitation. Companies should take immediate action to secure their devices and monitor for unusual activity. The findings underscore the importance of maintaining strong security practices and regularly updating credentials to mitigate these risks.

Jul 2, 2026

Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.

darkreading

IBM and Red Hat are launching a new initiative called Project Lightwell, which involves deploying 20,000 engineers to address vulnerabilities identified by Anthropic's AI tool, Mythos. This comes amid growing concerns about the security of the open-source software supply chain, particularly as more companies rely on open-source components. The findings from Mythos have sparked discussions in the tech community about how to better secure these systems and prevent potential exploitation. This investment reflects a significant commitment to improving software security, especially in light of increasing cyber threats targeting open-source software. As organizations continue to adopt open-source solutions, ensuring their safety becomes crucial to protecting sensitive data and maintaining system integrity.

Jul 2, 2026