Back to news

Iberian Banking Trojan Emerges as Scattered Spider Members Enter Guilty Pleas

Two cybersecurity developments this week underscore persistent threats from both organized cybercrime groups and stealthy banking malware targeting European financial users.

Iberian Banking Trojan Emerges as Scattered Spider Members Enter Guilty Pleas

What happened

Fortinet's FortiGuard Labs flagged an active campaign in May 2026 deploying Ousaban, a Brazilian-origin banking trojan, against Windows users at financial institutions in Spain and Portugal. Attackers lure victims with phishing emails carrying PDFs designed to appear corrupted, while the actual malware payload is concealed within an image file — a technique known as steganography. The campaign includes geofencing logic that verifies a visitor's location before delivering the payload, narrowing its targeting to Iberian IP addresses. Separately, two members of the Scattered Spider cybercrime collective entered guilty pleas in a UK court this week, on the first day of what had been scheduled as a six-week trial, over their roles in the August 2024 attack that severely disrupted Transport for London's operations.

Why it matters for your business

The Ousaban campaign illustrates how threat actors are layering evasion techniques — fake file corruption, geographic filtering, and image-based payload hiding — to slip past conventional email and endpoint defenses. Organizations with employees banking or conducting financial operations in Spain or Portugal face elevated risk and should audit phishing awareness training to include decoy-document scenarios. The Scattered Spider guilty pleas, meanwhile, confirm that even loosely organized, English-speaking cybercrime groups can inflict serious operational damage on critical infrastructure, with real legal consequences following. The practical takeaway: multi-factor authentication, zero-trust access controls, and regular tabletop exercises are not optional hygiene — they are the baseline that determined attackers probe first.

What to watch next

Sentencing in the UK Scattered Spider case is expected to follow the guilty pleas, and legal observers anticipate the proceedings will reveal further details about the group's tactics and potential co-conspirators still at large. On the malware front, security teams should monitor whether the Ousaban operators expand their targeting beyond the Iberian Peninsula, given that similar Brazilian banking trojans have historically broadened their geographic scope after initial regional deployments. Updated indicators of compromise from Fortinet's FortiGuard Labs are expected to be published, and defenders should prioritize ingesting those into SIEM and email gateway platforms promptly.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp