eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)

2026-06-19T13:23:47Z757f213e5a9bd4b0634e06599a1df22afc840de17dfe4e9a6d8a4f19f5986635
IPv4‑mapped‑IPv6IPv6JavaScriptRemcosSHA256:a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b8VHDXZIPemaile‑bankingmalicious‑linkmalwarephishing

What happened

SANS ISC diary roundup (Jun 12–19, 2026) highlighting multiple active threats and analysis: a targeted e‑banking phishing campaign using IPv4‑mapped IPv6 addresses to host malicious links (targets a major Belgian bank); a malicious ZIP (SHA256 a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094) that contains a VHDX which auto‑mounts and exposes a JavaScript dropper leading to a Remcos RAT; analysis of image‑based malicious payload techniques ("Evil MSI Background" / steganography); a guest diary on coordinated SSH brute‑force behavior over recent months; and a writeup on browser‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
757f213e5a9bd4b0634e06599a1df22afc840de17dfe4e9a6d8a4f19f5986635
Enrichment time
2026-06-19T13:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th) · Baitaphish