Fake Troubleshooting Prompts Trick Online Banking Users in Spain and Portugal into Installing Trojans 

Published
Written by:
Vishwa Pandagle
Vishwa Pandagle
Cybersecurity Staff Editor

Question: Your report about the ongoing Ousaban attacks targeting the Iberian Peninsula says that the malware checks whether it is running in a targeted environment. What does it reveal about potential victims?

Rachael Liao, FortiGuard Labs Analyst at Fortinet

The threat actor only allows access from Spain and Portugal. Based on the source code of a previous version of the webpage, from which the next stage is downloaded, more detailed configurations were implemented to restrict access exclusively to users connecting from Spain and Portugal.

Question: About geofencing or location-aware techniques that limited the campaign to intended victims, and how did those mechanisms help the operators remain under the radar? 

Rachael: Restricting access to users from other countries makes it more difficult for security analysts, automated sandboxes, and web archiving services to collect the malware. Analysts must spend additional time identifying an environment that can bypass the geographic restrictions, while automated analysis tools are less likely to adapt their environments to match the specific conditions required to access the malicious content.

Question: Fortiguard Labs identifies several financial institutions that are impersonated in the campaign. What should banks and other financial organizations prioritize to detect this activity and implement defensive measures? 

Rachael: The C2 mechanism is triggered when the victim visits a webpage belonging to one of the banks on the target list. The C2 server then instructs Ousaban to display a fake window that impersonates a message from the bank the victim is currently visiting.

Question: What are the measures for preventing customers and employees from reaching the final malware stage?

Rachael: The threat actor uses fake error messages to trick users into downloading the malware, making them believe they are performing legitimate troubleshooting steps. Therefore, user education and phishing awareness training are incredibly important to help users recognize and avoid these types of social engineering attacks.

Question: The campaign relies on either ClickFix or a phishing page before delivering the MSI installer. Why do these infection chains continue to appear legitimate to victims? What should users look for before the malware is executed?

Rachael: Many people today try to troubleshoot technical issues on their own. As a result, they may trust instructions or a "manual" presented by a seemingly malfunctioning system. Instead of following such on-screen instructions immediately, users should verify the error message by contacting their organization's IT support or the relevant support center directly for assistance.

Question: The malware uses an encryption algorithm that has remained effective at avoiding detection. What makes this implementation difficult for security tools to identify?

Rachael: The C2 commands are encrypted and represented as random alphanumeric data, making network-based detection and traffic analysis more challenging.

Question: At which point in the attack chain did you observe the greatest opportunity to detect and stop the intrusion before Ousaban established itself?

Rachael: All files are dropped to the victim's computer so AV software can just detect the related files to prevent execution.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: