eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)

2026-06-22T01:23:50Z1a9aca45d5d1dc205a0d8903fb3ddc82decc353d2a75adce6cf5af20f260bae6
banking-phishingbrowser-securitybrute-forcecredential-theftevasionimage-steganographyipv4-mapped-ipv6ipv6javascriptmalware-deliverymsiphishingratremcossans-iscsecurity-telemetryssh-bruteforcethreat-huntingvhdxzip

What happened

Collection of SANS ISC diary items (June 12–19, 2026) highlighting multiple threat observations: an eBanking phishing campaign that uses an IPv4‑mapped IPv6 address format to deliver phishing content (targeting a major Belgian bank), analysis of a malicious ZIP that contains a VHDX which auto-mounts and exposes a malicious JavaScript leading to a Remcos RAT (SHA256 of the reported ZIP: a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094), coordinated SSH brute‑force activity telemetry over three months, a guest diary on browser security “blind spots” where protections may be evad­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
1a9aca45d5d1dc205a0d8903fb3ddc82decc353d2a75adce6cf5af20f260bae6
Enrichment time
2026-06-22T01:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.