eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)

2026-06-21T19:23:47Z7584fd610cdb6a3ba7c13e55deec121d884a1d0c9cba49d8cbb6f4eb2c5f5455
IPv4-mapped-IPv6IPv6ISC SANSMSIRATRemcosSSH brute-forceVHDXZIPbrowser-visibilityeBankingimage-steganographymalicious-JavaScriptphishingsha256:a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b8threat-intel

What happened

SANS ISC diary feed (mid-June 2026) covering multiple security items: an eBanking phishing campaign using an IPv4-mapped IPv6 address targeting a major Belgian bank; a malicious ZIP containing a VHDX that auto-mounts and drops a JavaScript leading to a Remcos RAT (ZIP/VHDX SHA256: a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094); analysis of coordinated SSH brute-force activity; a guest diary on browser blind spots affecting security tools; and analysis of image/MSI steganography (“Evil MSI Background”). Several daily Stormcast podcast entries are also listed.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
7584fd610cdb6a3ba7c13e55deec121d884a1d0c9cba49d8cbb6f4eb2c5f5455
Enrichment time
2026-06-21T19:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.