Brazilian Banking Trojan Lures Users with Fake PDF

A brazilian banking trojan known as Ousaban is targeting Spanish and Portugese banks. It uses fake PDFs and a fake "update" button to trick users into opening a new browser tab, which then installs the malware onto their device. The malware is hidden inside an image, also known as steganography, to bypass initial anti-malware softwares. It uses session hijacking, which bypasses multi-factor authentication, to gain access to a user's bank account. The trojan drains funds from the account and is able to avoid detection from populare malware detection through its strict geofencing. The server used for command and controlling the malware is hidden, making it difficult for researchers to pinpoint and shut down the spread of the virus.