# Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL Extraction

> An active phishing campaign impersonating the Belgian bank Belfius delivers malicious links obfuscated as IPv4-mapped IPv6 addresses (e.g. http://[::ffff:5511:74be]/kWC5PHA1, which decodes to 85.17.116.190 on LeaseWeb) to defeat regex-based IP/domain extraction and signature controls. Victims who follow the bracketed-IPv6 URL are redirected to a Belfius-branded credential-harvesting kit hosted on a free FreeDNS subdomain (3439-aanmelden.verificatie.qzz.io/mon-belfius).

- **Published:** 2026-06-19T00:00:00Z
- **Last reviewed:** 2026-06-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0865
- **ID:** TL-2026-0865
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-06-19, SANS Internet Storm Center handler Xavier Mertens documented a credential-phishing campaign targeting customers of Belfius, one of Belgium's largest banks. The campaign's novelty is its initial-access lure URL, which encodes the destination host as an IPv4-mapped IPv6 address in RFC 4291 bracket notation rather than as a conventional IPv4 dotted-quad or domain name: hxxp://[::ffff:5511:74be]/kWC5PHA1.

The notation [::ffff:5511:74be] is the compressed form of the full IPv6 address 0000:0000:0000:0000:0000:ffff:5511:74be. The ::ffff: prefix is the standardized IPv4-mapped IPv6 prefix defined in RFC 4291 section 2.5.5.2; the final 32 bits encode the embedded IPv4 address. The two trailing 16-bit hex groups 5511 and 74be decode octet-by-octet: 0x55=85, 0x11=17, 0x74=116, 0xBE=190, yielding the real IPv4 address 85.17.116.190. That address sits in LeaseWeb Netherlands space (85.17.0.0/16, AS60781).

The purpose of the encoding is evasion. Many lightweight URL/IOC extractors, mail-gateway link rewriters, and signature engines rely on simple regular expressions that match dotted-decimal IPv4 patterns or hostname patterns. A bracketed, hex-compressed IPv4-mapped IPv6 literal does not match those patterns, so the malicious host can slip past naive domain/IP harvesting and reputation lookups. Mertens notes that no DNS record existed for the obfuscated address — the browser parses the literal directly to the embedded IPv4 host, so there is no resolver event to inspect or block.

When a victim opens the bracketed-IPv6 link, the host at 85.17.116.190 redirects the browser to a second-stage phishing page: hxxps://3439-aanmelden.verificatie.qzz.io/mon-belfius. The hostname is built on qzz.io, a free dynamic-DNS / free-subdomain service (FreeDNS-style, associated with DigitalPlat free-domain offerings) that has a documented history of abuse and a low reputation score; such services let attackers stand up throwaway, brand-adjacent subdomains (here the Dutch/French words 'aanmelden' = 'log in' and 'verificatie' = 'verification', plus 'mon-belfius', the brand name of Belfius's mobile banking app) with no verification and valid TLS, lending the page false legitimacy. The /mon-belfius page presents a Belfius-branded login form that captures the victim's online-banking credentials for financial fraud.

This activity is consistent with the long-running stream of Belfius-impersonation phishing tracked by Belgium's Safeonweb / CERT.be, which has repeatedly warned of fake Belfius login and 'check your messages' lures. The distinguishing tradecraft here is purely the delivery-layer obfuscation (IPv4-mapped IPv6) layered on top of commodity phishing-kit infrastructure on bulletproof-adjacent hosting and free DNS.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1566 Phishing
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1684.001 Impersonation
- T1598 Phishing for Information
- T1056 Input Capture
- T1071 Application Layer Protocol
- T1657 Financial Theft

## Sources

- [eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address (ISC Diary)](https://isc.sans.edu/diary/rss/33090)
- [RFC 4291 - IP Version 6 Addressing Architecture (IPv4-Mapped IPv6 Address, sec. 2.5.5.2)](https://www.rfc-editor.org/rfc/rfc4291)
- [New phishing messages on behalf of Belfius (Safeonweb / CERT.be)](https://safeonweb.be/en/news/new-phishing-messages-behalf-belfius)
- [An email from Belfius asking you to check your messages. Beware of phishing! (Safeonweb)](https://safeonweb.be/en/news/email-belfius-asking-you-check-your-messages-beware-phishing)
- [Ongoing abuse of afraid.org / free-DNS domains (Let's Encrypt Community)](https://community.letsencrypt.org/t/ongoing-abuse-of-afraid-org-domains/73095)
- [Qzz.io reputation / blacklist warning (Gridinsoft URL scanner)](https://gridinsoft.com/online-virus-scanner/url/qzz-io)
- [Belfius (corporate background)](https://en.wikipedia.org/wiki/Belfius)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0865
