eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)
2026-06-21T07:23:44Z•59a379af4f950cf890d80ec70cd5259f6f2ac9c5574b4ab28bf42a3e40b747b3
Evil MSI BackgroundIPv4-mapped-IPv6IPv6JavaScriptMSIRATRemcosSSH brute-forceURL obfuscationVHDXauto-mountbrowser blind spotcredential stuffingeBankingimage steganographymalicious ZIPphishingsecurity toolingweb security
What happened
SANS ISC diary items (mid‑June 2026) report multiple active threats: an e‑banking phishing campaign that uses IPv4‑mapped IPv6 addresses in URLs to evade detection and target a major Belgian bank; a Malicious ZIP containing a VHDX that auto‑mounts on modern Windows, exposing a JavaScript payload that leads to a Remcos RAT infection; renewed abuse of image/MSI techniques ('Evil MSI Background') for covert payload delivery; and trend analysis of coordinated SSH brute‑force activity plus a guest piece on browser blind spots and how security tools may not be blocking expected web threats.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 59a379af4f950cf890d80ec70cd5259f6f2ac9c5574b4ab28bf42a3e40b747b3
- Enrichment time
- 2026-06-21T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.