Threat reportPhishingTL-2026-0865
Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL Extraction
Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 (TL-2026-0865), also tracked as mon-belfius phishing, is a high-severity phishing campaign, first published 2026-06-19. It has no confirmed attribution, affects Belfius Bank Belfius online and mobile banking (mon-belfius / Belfius, maps to 10 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 19 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-0865
- Threat ID
- TL-2026-0865
- Also known as
- mon-belfius phishing, IPv4-mapped IPv6 phishing
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- financial, banking, consumer
- Target regions
- Belgium, Europe
- Detection rules
- 9
- Indicators of compromise
- 19
How Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 works
An active phishing campaign impersonating the Belgian bank Belfius delivers malicious links obfuscated as IPv4-mapped IPv6 addresses (e.g. http://[::ffff:5511:74be]/kWC5PHA1, which decodes to 85.17.116.190 on LeaseWeb) to defeat regex-based IP/domain extraction and signature controls. Victims who follow the bracketed-IPv6 URL are redirected to a Belfius-branded credential-harvesting kit hosted on a free FreeDNS subdomain (3439-aanmelden.verificatie.qzz.io/mon-belfius).
On 2026-06-19, SANS Internet Storm Center handler Xavier Mertens documented a credential-phishing campaign targeting customers of Belfius, one of Belgium's largest banks. The campaign's novelty is its initial-access lure URL, which encodes the destination host as an IPv4-mapped IPv6 address in RFC 4291 bracket notation rather than as a conventional IPv4 dotted-quad or domain name: hxxp://[::ffff:5511:74be]/kWC5PHA1.
The notation [::ffff:5511:74be] is the compressed form of the full IPv6 address 0000:0000:0000:0000:0000:ffff:5511:74be. The ::ffff: prefix is the standardized IPv4-mapped IPv6 prefix defined in RFC 4291 section 2.5.5.2; the final 32 bits encode the embedded IPv4 address. The two trailing 16-bit hex groups 5511 and 74be decode octet-by-octet: 0x55=85, 0x11=17, 0x74=116, 0xBE=190, yielding the real IPv4 address 85.17.116.190. That address sits in LeaseWeb Netherlands space (85.17.0.0/16, AS60781).
The purpose of the encoding is evasion. Many lightweight URL/IOC extractors, mail-gateway link rewriters, and signature engines rely on simple regular expressions that match dotted-decimal IPv4 patterns or hostname patterns. A bracketed, hex-compressed IPv4-mapped IPv6 literal does not match those patterns, so the malicious host can slip past naive domain/IP harvesting and reputation lookups. Mertens notes that no DNS record existed for the obfuscated address — the browser parses the literal directly to the embedded IPv4 host, so there is no resolver event to inspect or block.
When a victim opens the bracketed-IPv6 link, the host at 85.17.116.190 redirects the browser to a second-stage phishing page: hxxps://3439-aanmelden.verificatie.qzz.io/mon-belfius. The hostname is built on qzz.io, a free dynamic-DNS / free-subdomain service (FreeDNS-style, associated with DigitalPlat free-domain offerings) that has a documented history of abuse and a low reputation score; such services let attackers stand up throwaway, brand-adjacent subdomains (here the Dutch/French words 'aanmelden' = 'log in' and 'verificatie' = 'verification', plus 'mon-belfius', the brand name of Belfius's mobile banking app) with no verification and valid TLS, lending the page false legitimacy. The /mon-belfius page presents a Belfius-branded login form that captures the victim's online-banking credentials for financial fraud.
This activity is consistent with the long-running stream of Belfius-impersonation phishing tracked by Belgium's Safeonweb / CERT.be, which has repeatedly warned of fake Belfius login and 'check your messages' lures. The distinguishing tradecraft here is purely the delivery-layer obfuscation (IPv4-mapped IPv6) layered on top of commodity phishing-kit infrastructure on bulletproof-adjacent hosting and free DNS.
MITRE ATT&CK techniques used in TL-2026-0865
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Collection
Command and Control
T1071 Application Layer Protocol
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1608 Stage Capabilities
Reconnaissance
T1598 Phishing for Information
Impact
stealth
Affected products and versions in Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6
- Belfius Bank — Belfius online and mobile banking (mon-belfius / Belfius Mobile)
Vulnerable versions: customer credentials targeted via brand impersonation
Remediation for Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6
Immediate actions
- Block the host 85.17.116.190 and the CIDR context 85.17.0.0/16 at the perimeter where operationally feasible
- Block/sinkhole the phishing domain 3439-aanmelden.verificatie.qzz.io and consider blocking the qzz.io parent on mail/web gateways
- Add the obfuscated literal URL http://[::ffff:5511:74be]/kWC5PHA1 and its decoded form to email and proxy blocklists
- Alert customers and staff that any Belfius 'verification/login' link resolving to a bracketed-IPv6 or raw-IP host is fraudulent
Workarounds
- Configure secure web gateways to deny direct navigation to IP-literal and IPv6-literal URLs for end users
- Strip or rewrite raw IP-literal links in inbound mail and replace with safe-link interstitials that perform IPv6 canonicalization
Longer-term hardening
- Upgrade URL/IOC extraction regexes and mail-gateway parsers to canonicalize IPv4-mapped IPv6 literals ([::ffff:a.b.c.d] and [::ffff:XXXX:XXXX]) back to their embedded IPv4 address before reputation lookup
- Enforce phishing-resistant MFA (FIDO2/passkeys) on eBanking so harvested static credentials are insufficient for account takeover
- Deploy proxy/DNS controls that flag newly-observed free-DNS subdomains (qzz.io, afraid.org-style) hosting bank brand keywords
Timeline of Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6
- RFC 4291 defines the IPv4-mapped IPv6 address format (::ffff:0:0/96) later abused by this campaign for URL obfuscation.
- Belgium's Safeonweb / CERT.be warns of Belfius-impersonation phishing emails asking recipients to 'check your messages' — the long-running brand-impersonation stream this campaign continues.
- Safeonweb publishes a renewed alert about new phishing messages sent on behalf of Belfius, confirming sustained targeting of the bank's customers.
- Campaign added to Threadlinqs Intelligence as TL-2026-0865 for detection and IOC coverage of the novel evasion TTP.
- ISC diary documenting the IPv4-mapped IPv6 evasion technique and IOCs is published.
- Host 85.17.116.190 redirects victims to the Belfius-branded credential page hxxps://3439-aanmelden.verificatie.qzz.io/mon-belfius on a free FreeDNS subdomain.
- Obfuscated literal [::ffff:5511:74be] decoded to embedded IPv4 address 85.17.116.190 (LeaseWeb Netherlands, AS60781); no DNS record exists for the literal.
- SANS ISC handler Xavier Mertens observes the Belfius phishing lure using the bracketed IPv4-mapped IPv6 URL hxxp://[::ffff:5511:74be]/kWC5PHA1.
Sources cited for Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6
- eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address (ISC Diary)
- RFC 4291 - IP Version 6 Addressing Architecture (IPv4-Mapped IPv6 Address, sec. 2.5.5.2)
- New phishing messages on behalf of Belfius (Safeonweb / CERT.be)
- An email from Belfius asking you to check your messages. Beware of phishing! (Safeonweb)
- Ongoing abuse of afraid.org / free-DNS domains (Let's Encrypt Community)
- Qzz.io reputation / blacklist warning (Gridinsoft URL scanner)
- Belfius (corporate background)
Detection coverage for TL-2026-0865
As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0865 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0865
1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.