IOC Radar
TLP:WHITE3 IOCs

Ousaban Banking Trojan Targets Spain and Portugal With Geofenced Phishing Campaign

CP
Cyber Press
Published July 2, 2026Original Report

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREfacture-in.pages.devfacture-arsys.duckdns…faturanova.xyzCAPABILITYunknownVICTIMunknown
Adversary
Infrastructure(3)
Capability
Victim

Attack Flow8 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1566
1/8
Phishing
ActionDeliver phishing PDF
Victim receives a phishing PDF disguised as a corrupted file, prompting an update.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise3

TypeIndicatorConfidenceScoreFirst Seen
Domainfacture-in.pages.dev
indicatorintel-blognetwork
High
58
Jul 2, 26
Domainfacture-arsys.duckdns.org
indicatorintel-blognetwork
High
58
Jul 2, 26
Domainfaturanova.xyz
indicatorintel-blognetwork
High
58
Jul 2, 26

IOC Relationship Graph

IOC Relationship Graph3 total IOCs
Domain
Domain3REPORTOusaban Banking Trojan Tar
scroll to zoom · drag to pan · click IOC to open