eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)
2026-06-19T07:23:48Z•c3fc5f10f38cce6d80b2db9628244fea5f197fefc304af8689ee5b77c8b4f0dd
IPv4-mapped-IPv6IPv6JavaScriptRATRemcosSANS-ISCSSH brute forceURL-evasionVHDXbrowser blind spotcredential attackseBankingevil-msi-backgroundmalicious-zipphishingsecurity-telemetrysteganographythreat-intel
What happened
SANS ISC diary feed (mid-June 2026) covering multiple active threats and analysis: an eBanking phishing campaign that used an IPv4‑mapped IPv6 address to deliver a Belgian bank phishing page; a VHDX-based dropper inside a malicious ZIP (SHA256 a0104921a2d37ab...) that exposes JavaScript leading to a Remcos RAT; coordinated SSH brute‑force behavior analysis; discussion of browser-based blind spots affecting security controls; and analysis of image/MSI-based malicious content. Also includes routine ISC Stormcast podcast entries and guest diaries.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c3fc5f10f38cce6d80b2db9628244fea5f197fefc304af8689ee5b77c8b4f0dd
- Enrichment time
- 2026-06-19T07:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.