Protect.Computer
NEWS

Fake Tax PDFs Steal Bank Logins from Spanish and Portuguese Users

· 1 min read · Digital scams Malicious byte
Fake Tax PDFs Steal Bank Logins from Spanish and Portuguese Users

Cybersecurity researchers at Fortinet have uncovered a campaign targeting bank customers in Spain and Portugal. Attackers are sending phishing emails that appear to come from official sources, containing what looks like a PDF tax or invoice document. When you open it, the file shows a fake error and prompts you to click an “Update” button — doing so silently installs Ousaban, a banking trojan that records your keystrokes and takes screenshots whenever you log in to your bank’s website.

The malware specifically targets customers of over 20 banks, including Santander, BBVA, CaixaBank, Bankinter, and Caixa Geral de Depósitos. Once installed on a Windows computer, it stays hidden in the background and relays your banking credentials to the attackers in real time. The campaign uses a clever trick to stay stealthy: its command-and-control server address changes every day based on a coded formula, making it hard for security tools to block.

How to check if you’re affected

Affected devices are Windows computers used for online banking at Santander, BBVA, CaixaBank, Bankinter, Caixa Geral de Depósitos, or other banks in Spain or Portugal:

  1. Never open PDF attachments from unexpected emails, especially ones that show an error message and ask you to click “Update” or “Atualizar.” Real bank documents don’t prompt you to install anything.
  2. If you recently opened a suspicious PDF, run a full scan with your antivirus software. Windows Security (built-in) can be launched from Start → Windows Security → Virus & threat protection → Quick scan.
  3. Call your bank directly using the phone number on your card if you see any unrecognized transactions or if you’ve opened a suspicious attachment in the last few weeks.

Sources

Related reading