Threat reportPhishingTL-2026-0865

Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL Extraction

highACTIVE

Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 (TL-2026-0865), also tracked as mon-belfius phishing, is a high-severity phishing campaign, first published 2026-06-19. It has no confirmed attribution, affects Belfius Bank Belfius online and mobile banking (mon-belfius / Belfius, maps to 10 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 19 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
19Indicators of compromise

Key facts for TL-2026-0865

Threat ID
TL-2026-0865
Also known as
mon-belfius phishing, IPv4-mapped IPv6 phishing
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
financial, banking, consumer
Target regions
Belgium, Europe
Detection rules
9
Indicators of compromise
19

How Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 works

An active phishing campaign impersonating the Belgian bank Belfius delivers malicious links obfuscated as IPv4-mapped IPv6 addresses (e.g. http://[::ffff:5511:74be]/kWC5PHA1, which decodes to 85.17.116.190 on LeaseWeb) to defeat regex-based IP/domain extraction and signature controls. Victims who follow the bracketed-IPv6 URL are redirected to a Belfius-branded credential-harvesting kit hosted on a free FreeDNS subdomain (3439-aanmelden.verificatie.qzz.io/mon-belfius).

On 2026-06-19, SANS Internet Storm Center handler Xavier Mertens documented a credential-phishing campaign targeting customers of Belfius, one of Belgium's largest banks. The campaign's novelty is its initial-access lure URL, which encodes the destination host as an IPv4-mapped IPv6 address in RFC 4291 bracket notation rather than as a conventional IPv4 dotted-quad or domain name: hxxp://[::ffff:5511:74be]/kWC5PHA1.

The notation [::ffff:5511:74be] is the compressed form of the full IPv6 address 0000:0000:0000:0000:0000:ffff:5511:74be. The ::ffff: prefix is the standardized IPv4-mapped IPv6 prefix defined in RFC 4291 section 2.5.5.2; the final 32 bits encode the embedded IPv4 address. The two trailing 16-bit hex groups 5511 and 74be decode octet-by-octet: 0x55=85, 0x11=17, 0x74=116, 0xBE=190, yielding the real IPv4 address 85.17.116.190. That address sits in LeaseWeb Netherlands space (85.17.0.0/16, AS60781).

The purpose of the encoding is evasion. Many lightweight URL/IOC extractors, mail-gateway link rewriters, and signature engines rely on simple regular expressions that match dotted-decimal IPv4 patterns or hostname patterns. A bracketed, hex-compressed IPv4-mapped IPv6 literal does not match those patterns, so the malicious host can slip past naive domain/IP harvesting and reputation lookups. Mertens notes that no DNS record existed for the obfuscated address — the browser parses the literal directly to the embedded IPv4 host, so there is no resolver event to inspect or block.

When a victim opens the bracketed-IPv6 link, the host at 85.17.116.190 redirects the browser to a second-stage phishing page: hxxps://3439-aanmelden.verificatie.qzz.io/mon-belfius. The hostname is built on qzz.io, a free dynamic-DNS / free-subdomain service (FreeDNS-style, associated with DigitalPlat free-domain offerings) that has a documented history of abuse and a low reputation score; such services let attackers stand up throwaway, brand-adjacent subdomains (here the Dutch/French words 'aanmelden' = 'log in' and 'verificatie' = 'verification', plus 'mon-belfius', the brand name of Belfius's mobile banking app) with no verification and valid TLS, lending the page false legitimacy. The /mon-belfius page presents a Belfius-branded login form that captures the victim's online-banking credentials for financial fraud.

This activity is consistent with the long-running stream of Belfius-impersonation phishing tracked by Belgium's Safeonweb / CERT.be, which has repeatedly warned of fake Belfius login and 'check your messages' lures. The distinguishing tradecraft here is purely the delivery-layer obfuscation (IPv4-mapped IPv6) layered on top of commodity phishing-kit infrastructure on bulletproof-adjacent hosting and free DNS.

MITRE ATT&CK techniques used in TL-2026-0865

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Collection

T1056 Input Capture

Command and Control

T1071 Application Layer Protocol

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

Reconnaissance

T1598 Phishing for Information

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6

  • Belfius Bank — Belfius online and mobile banking (mon-belfius / Belfius Mobile)
    Vulnerable versions: customer credentials targeted via brand impersonation

Remediation for Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6

Immediate actions

  • Block the host 85.17.116.190 and the CIDR context 85.17.0.0/16 at the perimeter where operationally feasible
  • Block/sinkhole the phishing domain 3439-aanmelden.verificatie.qzz.io and consider blocking the qzz.io parent on mail/web gateways
  • Add the obfuscated literal URL http://[::ffff:5511:74be]/kWC5PHA1 and its decoded form to email and proxy blocklists
  • Alert customers and staff that any Belfius 'verification/login' link resolving to a bracketed-IPv6 or raw-IP host is fraudulent

Workarounds

  • Configure secure web gateways to deny direct navigation to IP-literal and IPv6-literal URLs for end users
  • Strip or rewrite raw IP-literal links in inbound mail and replace with safe-link interstitials that perform IPv6 canonicalization

Longer-term hardening

  • Upgrade URL/IOC extraction regexes and mail-gateway parsers to canonicalize IPv4-mapped IPv6 literals ([::ffff:a.b.c.d] and [::ffff:XXXX:XXXX]) back to their embedded IPv4 address before reputation lookup
  • Enforce phishing-resistant MFA (FIDO2/passkeys) on eBanking so harvested static credentials are insufficient for account takeover
  • Deploy proxy/DNS controls that flag newly-observed free-DNS subdomains (qzz.io, afraid.org-style) hosting bank brand keywords

Timeline of Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6

  • RFC 4291 defines the IPv4-mapped IPv6 address format (::ffff:0:0/96) later abused by this campaign for URL obfuscation.
  • Belgium's Safeonweb / CERT.be warns of Belfius-impersonation phishing emails asking recipients to 'check your messages' — the long-running brand-impersonation stream this campaign continues.
  • Safeonweb publishes a renewed alert about new phishing messages sent on behalf of Belfius, confirming sustained targeting of the bank's customers.
  • Campaign added to Threadlinqs Intelligence as TL-2026-0865 for detection and IOC coverage of the novel evasion TTP.
  • ISC diary documenting the IPv4-mapped IPv6 evasion technique and IOCs is published.
  • Host 85.17.116.190 redirects victims to the Belfius-branded credential page hxxps://3439-aanmelden.verificatie.qzz.io/mon-belfius on a free FreeDNS subdomain.
  • Obfuscated literal [::ffff:5511:74be] decoded to embedded IPv4 address 85.17.116.190 (LeaseWeb Netherlands, AS60781); no DNS record exists for the literal.
  • SANS ISC handler Xavier Mertens observes the Belfius phishing lure using the bracketed IPv4-mapped IPv6 URL hxxp://[::ffff:5511:74be]/kWC5PHA1.

Sources cited for Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6

Detection coverage for TL-2026-0865

As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0865 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
19 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-0865

1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats