eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)
2026-06-22T01:23:50Z•1a9aca45d5d1dc205a0d8903fb3ddc82decc353d2a75adce6cf5af20f260bae6
banking-phishingbrowser-securitybrute-forcecredential-theftevasionimage-steganographyipv4-mapped-ipv6ipv6javascriptmalware-deliverymsiphishingratremcossans-iscsecurity-telemetryssh-bruteforcethreat-huntingvhdxzip
What happened
Collection of SANS ISC diary items (June 12–19, 2026) highlighting multiple threat observations: an eBanking phishing campaign that uses an IPv4‑mapped IPv6 address format to deliver phishing content (targeting a major Belgian bank), analysis of a malicious ZIP that contains a VHDX which auto-mounts and exposes a malicious JavaScript leading to a Remcos RAT (SHA256 of the reported ZIP: a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094), coordinated SSH brute‑force activity telemetry over three months, a guest diary on browser security “blind spots” where protections may be evad
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 1a9aca45d5d1dc205a0d8903fb3ddc82decc353d2a75adce6cf5af20f260bae6
- Enrichment time
- 2026-06-22T01:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.