Ousaban
Ousaban (canonical ESET naming per Dirty Dozen series "Ousaban: Private photo collection hidden in a CABinet" disclosure, title references signature CAB archive Cabinet delivery method distinctive cluster- defining tradecraft within LATAM banking trojan ecosystem) is a Brazilian-origin banking trojan + ESET Dirty Dozen LATAM banking trojan member with cluster-defining suspected Zumanek successor relation per ESET low-confidence assessment ("We think with low confidence that Ousaban may actually be the successor of Zumanek. Even though the two malware families don't seem to share any code similarities, their remote configuration format uses very similar delimiters. Additionally, we have observed several servers used by Ousaban that looked very much like those used by Zumanek in the past")
Brazilian- origin organized cybercrime attribution via ESET canonical Dirty Dozen entry + ESET December 15, 2021 retrospective Zumanek-successor identification + ESET telemetry-based Brazil-dominance Q3-Q4 2021 assessment + Threatpost canonical October 2020 industry coverage.
standalone malware platform cluster paralleling amavaldo + numando + vadokrist in v0.1.142 LATAM banking trojan operators cell expansion.
operational target profile Brazil dominant target per ESET 2021 telemetry alongside Casbaneiro ("While Grandoreiro remains dominant in Spain, Ousaban and Casbaneiro dominated Brazil in the latest months" + "In Q3 and Q4 2021, we have seen Grandoreiro, Ousaban and Casbaneiro increasing their reach enormously compared to their previous activity") + Portuguese-speaking countries focus; operational attack architecture: (1) fake banking pop-up overlay credential capture typical LATAM banking trojan tradecraft + backdoor functionality + screenshots + mouse/keyboard simulation + keystroke capture.
(2) cluster- defining CAB archive (Cabinet) delivery method signature ESET-disclosed delivery referenced in canonical Ousaban title, distinctive cluster- defining tradecraft within LATAM banking trojan ecosystem.
(3) Delphi programming language origin signature typical LATAM banking trojan codebase; (4) spam distribution typical LATAM banking trojan distribution.
(5) cluster-defining suspected Zumanek-successor signature per ESET, remote configuration format very similar delimiters + server overlap with historical Zumanek operations , low-confidence operator-relation tradecraft establishing operational lineage from earlier Zumanek malware family ESET first identified as Latin American banking trojan.
(6) cluster- defining 2021 Brazil dominance signature per ESET telemetry alongside Casbaneiro dominating Brazil banking trojan activity Q3-Q4 2021 with reach enormously increased compared to previous activity; cluster fills the ESET-Dirty-Dozen + CAB-archive- delivery + Zumanek-successor-suspected + Brazil- 2021-dominance position in Latin American banking trojan operators cell.
canonical illustration of ESET Dirty Dozen LATAM banking trojan + CAB archive Cabinet delivery tradecraft + suspected Zumanek successor lineage + Brazil 2021 dominance telemetry cited in essentially all subsequent Latin American banking trojan industry analyses through 2018-2026 period.