Webshells Remain Popular, (Mon, Jun 22nd)
2026-06-23T01:23:46Z•9853a816716d0afe4ce46833b9a56c29b007277a13d887d9ab5d876647b4d0c6
IPv4-mapped-IPv6MSIRATRemcosSSH brute forceVHDXZIPbrowser blind spotcoordinated attackseBankingevil backgroundgithubimage steganographymalicious JavaScriptphishingsecurity toolingthreat intelligencewebshell
What happened
Collection of SANS ISC diary highlights (Jun 15–22, 2026): webshells continue to be widely used (author spotted a newly published webshell on GitHub from ~2 months ago). A phishing campaign targeting a major Belgian bank used an IPv4-mapped IPv6 address delivery technique. Analysis of coordinated SSH brute-force activity over three months was published. A guest diary discusses a browser blind spot where security tools may not be blocking expected content. A malicious ZIP (SHA256 a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094) contained a VHDX that, when mounted, exposed a JS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 9853a816716d0afe4ce46833b9a56c29b007277a13d887d9ab5d876647b4d0c6
- Enrichment time
- 2026-06-23T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.