Home/Threat Actor/Ousaban
Threat Actor

Ousaban

ousaban · latin_america_brazilian_organized_cybercrime · active since 2018

Ousaban (canonical ESET naming per Dirty Dozen series "Ousaban: Private photo collection hidden in a CABinet" disclosure, title references signature CAB archive Cabinet delivery method distinctive cluster- defining tradecraft within LATAM banking trojan ecosystem) is a Brazilian-origin banking trojan + ESET Dirty Dozen LATAM banking trojan member with cluster-defining suspected Zumanek successor relation per ESET low-confidence assessment ("We think with low confidence that Ousaban may actually be the successor of Zumanek. Even though the two malware families don't seem to share any code similarities, their remote configuration format uses very similar delimiters. Additionally, we have observed several servers used by Ousaban that looked very much like those used by Zumanek in the past")

Brazilian- origin organized cybercrime attribution via ESET canonical Dirty Dozen entry + ESET December 15, 2021 retrospective Zumanek-successor identification + ESET telemetry-based Brazil-dominance Q3-Q4 2021 assessment + Threatpost canonical October 2020 industry coverage.

standalone malware platform cluster paralleling amavaldo + numando + vadokrist in v0.1.142 LATAM banking trojan operators cell expansion.

operational target profile Brazil dominant target per ESET 2021 telemetry alongside Casbaneiro ("While Grandoreiro remains dominant in Spain, Ousaban and Casbaneiro dominated Brazil in the latest months" + "In Q3 and Q4 2021, we have seen Grandoreiro, Ousaban and Casbaneiro increasing their reach enormously compared to their previous activity") + Portuguese-speaking countries focus; operational attack architecture: (1) fake banking pop-up overlay credential capture typical LATAM banking trojan tradecraft + backdoor functionality + screenshots + mouse/keyboard simulation + keystroke capture.

(2) cluster- defining CAB archive (Cabinet) delivery method signature ESET-disclosed delivery referenced in canonical Ousaban title, distinctive cluster- defining tradecraft within LATAM banking trojan ecosystem.

(3) Delphi programming language origin signature typical LATAM banking trojan codebase; (4) spam distribution typical LATAM banking trojan distribution.

(5) cluster-defining suspected Zumanek-successor signature per ESET, remote configuration format very similar delimiters + server overlap with historical Zumanek operations , low-confidence operator-relation tradecraft establishing operational lineage from earlier Zumanek malware family ESET first identified as Latin American banking trojan.

(6) cluster- defining 2021 Brazil dominance signature per ESET telemetry alongside Casbaneiro dominating Brazil banking trojan activity Q3-Q4 2021 with reach enormously increased compared to previous activity; cluster fills the ESET-Dirty-Dozen + CAB-archive- delivery + Zumanek-successor-suspected + Brazil- 2021-dominance position in Latin American banking trojan operators cell.

canonical illustration of ESET Dirty Dozen LATAM banking trojan + CAB archive Cabinet delivery tradecraft + suspected Zumanek successor lineage + Brazil 2021 dominance telemetry cited in essentially all subsequent Latin American banking trojan industry analyses through 2018-2026 period.

latin_america_brazilian_organized_cybercrime confidence: high 7 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Ousaban (canonical ESET naming per Dirty Dozen series "Ousaban: Private photo collection hidden in a CABinet" disclosure, title references signature CAB archive Cabinet delivery method) is a Brazilian- origin banking trojan + ESET Dirty Dozen LATAM banking trojan member with cluster-defining suspected Zumanek successor relation per ESET low-confidence assessment. Brazilian-origin organized cybercrime attribution via ESET canonical Dirty Dozen entry + ESET December 2021 retrospective Zumanek-successor identification + ESET telemetry-based Brazil-dominance Q3-Q4 2021 assessment. Standalone malware platform cluster paralleling amavaldo + numando + vadokrist in v0.1.142 LATAM banking trojan operators cell expansion.

Operational target profile
  • Brazil dominant target per ESET 2021 telemetry (alongside Casbaneiro)
  • Banking + financial institutions per ESET.
  • Portuguese-speaking countries focus Operational attack architecture: (1) Fake banking pop-up overlay credential capture (signature): typical LATAM banking trojan tradecraft (2) CAB archive (Cabinet) delivery (cluster- defining): signature ESET-disclosed delivery method referenced in canonical Ousaban title (3) Delphi programming language origin (signature) (4) Spam distribution typical LATAM (signature) (5) Suspected Zumanek-successor signature (cluster- defining): per ESET, "remote configuration format uses very similar delimiters" + "servers used by Ousaban that looked very much like those used by Zumanek in the past", low-confidence operator- relation tradecraft (6) 2021 Brazil dominance signature (cluster- defining): per ESET telemetry, alongside Casbaneiro dominating Brazil banking trojan activity Q3-Q4 2021 with reach enormously increased The cluster fills the ESET-Dirty-Dozen + CAB-archive- delivery + Zumanek-successor-suspected + Brazil- 2021-dominance position in the Latin American banking trojan operators cell.

Aliases

7
ousabanousaban_banking_trojanousaban_malwareousaban eset dirty dozen latin americaousaban private photo collection hidden cabinetousaban suspected zumanek successorousaban brazil banking trojan dominant 2021

Adversary Emulation Plan

4 steps
Runnable Caldera emulation profile Collection - A collection adversary. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 collection T1005 · Data from Local System darwin
Find company emails
find $(echo ~#{host.user.name}) -type f -size -500k -maxdepth 5 -exec grep -EIr -o "\b[A-Za-z0-9._%+-]+@#{target.org.name}\b" 2>/dev/null {} \;
1 collection T1005 · Data from Local System darwin
Find IP addresses
find $(echo ~#{host.user.name}) -type f -size -500k -maxdepth 5 -exec grep -EIr -o "(($(echo #{domain.broadcast.ip} | cut -d. -f-2))\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)" 2>/dev/null {} \;
2 collection T1005 · Data from Local System darwin, windows, linux
Find files
find /Users -name '*.#{file.sensitive.extension}' -type f -not -path '*/\.*' -size -500k 2>/dev/null | head -5
3 collection T1074.001 · Data Staged: Local Data Staging darwin, linux, windows
Create staging directory
mkdir -p staged && echo $PWD/staged

Notable Campaigns

5
2021Ousaban Q3-Q4 2021 Brazil Dominance Signature
2019-2021ESET Canonical Ousaban Dirty Dozen Disclosure
2018-2026Continued Industry Reference Status (2018-2026)
2018-2021Ousaban Suspected Zumanek Successor Signature
2018Ousaban Origin, Brazil (2018)

Attribution & Reporting

Key reporting
reportESET WeLiveSecurity: Ousaban, Private photo collection hidden in a CABinet (canonical Dirty Dozen entry)
reportESET WeLiveSecurity: The Dirty Dozen of Latin America, From Amavaldo to Zumanek (December 15, 2021), canonical retrospective with Zumanek-successor + Brazil dominance
reportThreatpost: LatAm Banking Trojans Collaborate (October 2020)
reportESET Research Team: canonical Latin American banking trojan white paper
reportMalpedia Software Profile: Ousaban

Operational

State sponsor

Brazilian-origin organized cybercrime, ESET Dirty Dozen LATAM banking trojan member, suspected successor of Zumanek per ESET. Operationally separate from state-sponsored APT activity. Attribution chain: (1) ESET canonical Dirty Dozen entry: per ESET WeLiveSecurity Dirty Dozen series, "Ousaban: Private photo collection hidden in a CABinet" canonical disclosure.

Operationally significant, title references signature CAB archive (Cabinet) delivery method. (2) ESET canonical Zumanek-successor identification December 2021: per ESET WeLiveSecurity Dirty Dozen retrospective: "We think with low confidence that Ousaban may actually be the successor of Zumanek. Even though the two malware families don't seem to share any code similarities, their remote configuration format uses very similar delimiters.

Additionally, we have observed several servers used by Ousaban that looked very much like those used by Zumanek in the past." Operationally significant operator-relation signature. (3) ESET canonical December 2021 Brazil-dominance telemetry: per ESET WeLiveSecurity Dirty Dozen retrospective: "While Grandoreiro remains dominant in Spain, Ousaban and Casbaneiro dominated Brazil in the latest months." Operationally significant Q3-Q4 2021 Brazil dominance signature alongside Casbaneiro. (4) ESET canonical Q3-Q4 2021 reach increase: per ESET: "In Q3 and Q4 2021, we have seen Grandoreiro, Ousaban and Casbaneiro increasing their reach enormously compared to their previous activity." Operationally significant active campaign expansion signature.

(5) Threatpost canonical October 2020 industry coverage: per Threatpost: "Multiple, distinct malware families have plagued Latin American banking customers for years
  • the variants include Amavaldo, Casbaneiro, Grandoreiro, Guildma, Krachulka, Lokorrito, Mekotio, Mispadu, Numando, Vadokrist and Zumanek, according to ESET", Ousaban + Zumanek relation tracked. Operational mission objective: Banking credential theft via fake pop-up overlay tradecraft + backdoor functionality. Typical LATAM banking trojan operational pattern.
Operational target profile
  • Brazil dominant target per ESET 2021 telemetry.
  • Banking + financial institutions per ESET.
  • Portuguese-speaking countries focus The cluster fills the ESET-Dirty-Dozen + CAB-archive- delivery + Zumanek-successor-suspected position in the Latin American banking trojan operators cell.
Motivations
banking_credential_theft_brazil_dominant_targeting, eset_dirty_dozen_canonical_entry_status, zumanek_successor_suspected_per_eset_low_confidence, cab_archive_cabinet_delivery_signature_tradecraft, 2021_brazil_dominance_alongside_casbaneiro_telemetry
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)26/60 · 43%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin