home.social

#bankingtrojan — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bankingtrojan, aggregated by home.social.

fetched live
  1. Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

    In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.

    Pulse ID: 6a45880f3df872860c77a553
    Pulse Link: otx.alienvault.com/pulse/6a458
    Pulse Author: AlienVault
    Created: 2026-07-01 21:35:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault

  2. Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

    In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.

    Pulse ID: 6a45880f3df872860c77a553
    Pulse Link: otx.alienvault.com/pulse/6a458
    Pulse Author: AlienVault
    Created: 2026-07-01 21:35:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault

  3. Ousaban Trojan Expands to Spain, Portugal with Advanced Evasion Tactics

    Meet Ousaban, a sneaky banking Trojan that's evolved from decade-old tactics to target unsuspecting customers in Spain and Portugal, starting with a clever phishing PDF disguised as a broken file. This highly optimized threat profiles its victims before striking, making it a force to be reckoned with.

    osintsights.com/ousaban-trojan

    #BankingTrojan #Ousaban #Spain #Portugal #Phishing

  4. 📰 New TCLBANKER Trojan Spreads via WhatsApp and Outlook, Targeting 59 Brazilian Financial Apps

    🇧🇷 New Banking Trojan 'TCLBANKER' targets 59 Brazilian financial apps! The malware spreads like a worm via WhatsApp & Outlook, using DLL side-loading to evade detection. Stay vigilant! 💻 #Malware #BankingTrojan #Brazil #Cybersecurity

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ne

  5. 📰 Grandoreiro Banking Trojan Resurges, Targeting Banks in Spain and Latin America

    Grandoreiro banking trojan is back. 📈 New campaigns are targeting banks and customers in Spain and Latin America, using phishing and DLL side-loading to steal credentials with fake overlays. 🏦 #Grandoreiro #Malware #BankingTrojan #Phishing #Fintech

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/gr

  6. Banking Trojan Targets Crypto Firms with Sophisticated Attacks

    A new banking Trojan, dubbed TCLBanker, is wreaking havoc on crypto and finance platforms, allowing hackers to remotely control infected systems and steal sensitive info. This sophisticated attack, linked to North Korea's notorious Lazarus Group, has already led to the largest crypto platform hack of 2026.

    osintsights.com/banking-trojan

    #Tclbanker #BankingTrojan #LazarusGroup #NorthKorea #CryptoFirms

  7. 🚨 Alert: The new #EternidadeStealer is using WhatsApp to spread malicious files to steal banking and crypto data from users. Watch out and don’t open unexpected attachments, plus verify messages from contacts.

    Read: hackread.com/eternidade-steale

    #CyberSecurity #Malware #WhatsApp #BankingTrojan #InfoSec

  8. 🚨 Alert: The new #EternidadeStealer is using WhatsApp to spread malicious files to steal banking and crypto data from users. Watch out and don’t open unexpected attachments, plus verify messages from contacts.

    Read: hackread.com/eternidade-steale

    #CyberSecurity #Malware #WhatsApp #BankingTrojan #InfoSec