IPv4 Mapped IPv6 Addresses, (Tue, Mar 17th)
2026-03-18T07:23:46Z•5aecc0413ffee6e802641b588ef66665afdfe96a8c9918100dc18c7c1352810c
CVE-2026-0866credential-theftdefault-credentialsemailjshoneypot-telemetryhost-header-injectioniotipv4-mapped-ipv6ipv6malwarephishingproxy-scansratreactremcossmartapesgthreat-intelvulnerabilityzombie-zip
What happened
Multiple ISC diary entries report active reconnaissance and phishing/malware campaigns: attackers are abusing IPv4-mapped IPv6 addresses (RFC 4038) to obfuscate scans and proxy abuse (including /proxy/ URL probes and host-header tricks); a React-based phishing page was observed exfiltrating credentials via the legitimate EmailJS service; the SmartApeSG campaign is delivering the Remcos RAT using a ClickFix-themed page; insecure IoT devices logging in as admin (default/weak credentials) are highlighted as a persistent risk; and a new vulnerability, “Zombie Zip” (CVE-2026-0866), was published.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 5aecc0413ffee6e802641b588ef66665afdfe96a8c9918100dc18c7c1352810c
- Enrichment time
- 2026-03-18T07:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.