IPv4-Mapped IPv6 Literals: A Long-Running CTA Obfuscation Toolkit
IPv4-Mapped IPv6 Literals: A Long-Running CTA Obfuscation Toolkit
Over five months beginning in December 2025, one email operator hid phishing links inside IPv4-mapped IPv6 URL literals to evade reputation scanners. The notation resembles line noise, http[:]//[0000:0000:0000:0000:0000:ffff:c0e3:b86d]/qs=r-..., but a dual-stack browser dials it as a plain IPv4 server. This trick anchored a campaign that rotated through 2,423 sending domains and roughly 200 disposable virtual servers while retaining the same delivery grammar. The lures changed weekly. The obfuscated destination did not.
Key Takeaways
- The operator wrapped every call-to-action in an IPv4-mapped IPv6 literal (
[::ffff:aabb:ccdd]). Most URL and IP extractors never normalize this notation, so host and domain reputation systems could not see the real destination. - Sending and delivery were separate: 3,498 rotating sender addresses across 2,423 domains all fed into one reusable CTA path (
/qs=r-<~70-char hex>) that pointed to a shared pool of roughly 200 bare-IP virtual servers. - WHOIS divides the sender domains into two clear cohorts: aged domains consistent with compromised small businesses, and a purpose-built Namecheap monoculture registered days to weeks before use.
- The coined CTA apexes used
.info, whose registry returns no WHOIS to most indexers. The operator chose it to create a reputation blind spot. - In April 2026, the campaign consolidated its lure surface around cloud-storage credential phishing. A tight registration cluster of new fake-word
.infodomains shows the change.
Background
The campaign first appeared in a handful of email samples with an unusual call-to-action. Rather than a hostname or dotted-decimal IP, each link contained a bracketed IPv6 address with an ::ffff: prefix. The prefix itself is not exotic. RFC 4291 defines it as the IPv4-mapped IPv6 format, a transition mechanism that embeds a 32-bit IPv4 address in the low bits of a 128-bit IPv6 address. It can be written as ::ffff:a.b.c.d or, in pure hex, as ::ffff:aabb:ccdd. When placed in a URL authority, http[:]//[::ffff:aabb:ccdd]/path, it causes a dual-stack client to resolve and dial the underlying IPv4 host directly. No DNS lookup occurs because there is no hostname.
Its value to the operator comes from a defensive gap. Most rule-based URL and IP extractors look for hostnames or dotted-decimal addresses. A bracketed hex literal is neither. Unless a scanner normalizes the notation, it sees a meaningless string instead of the actual server address. Public reporting has covered the technique only in isolated, single-sample write-ups. SANS ISC identified the notation as a detection-bypass format in December 2023. In June 2026, it documented a live eBanking phishing sample with the same [::ffff:...] shape and noted that the bracket literal defeats simple regular expressions and carries no DNS record. The public record did not describe a long-running, multi-domain, telemetry-instrumented operation built around the technique. We mapped one here.
The campaign follows the familiar snowshoe model: distribute sending across many domains and servers so that no single indicator gains enough weight to cross a reputation threshold, then discard each identifier before it is blocked. Snowshoe sending is well documented as a spam-reputation-dilution tactic. What differs here is the delivery layer receiving that traffic.
Discovery and Infrastructure
The infrastructure has two deliberately separate layers.
The sender layer changes constantly. During the observation window, the operator used 3,498 distinct From-addresses across 2,423 domains, including country-code and generic TLDs (.co.jp, .mx, .nl, .uk, .de, .dk, .info, .org, .us, .biz, and more). It pushed hundreds of thousands of messages through this apparatus. There was no hub domain. In any recent 60-day slice, the busiest domain carried only a few dozen messages before the distribution dropped to one or two per domain. The volume came from the size of the field, not any individual sender. Most domains lasted a day or two.
The delivery layer barely changed. Every vertical, sender cohort, and pretext ended with the same call-to-action grammar: an IPv4-mapped IPv6 literal followed by /qs=r- and roughly seventy hex characters. We observed 1,322 unique IPv6-literal hosts, which reduce to a little over 200 unique IPv4 backends after decoding. These backends were bare HTTP endpoints on low-reputation virtual-server providers, with no hostname, no TLS, and no virtual-hosting. Each was cheap to set up and slow to be de-listed.
The delivery layer had effectively no reputation coverage. The URL indexer does not normalize IPv6-literal notation, leaving the entire /qs=r- rail outside host and domain reputation systems. A sweep of the decoded backends found a reputation record for exactly one address, and that record was unflagged. The operator did not need bulletproof hosting to remain hidden. The notation concealed the infrastructure.
How It Works
A representative message arrives from a domain with clean authentication. SPF, DKIM, and DMARC all align because the sender either controls a compromised legitimate domain outright or registered a throwaway domain and published its own records. Authentication proves custody of the domain, not honest intent. In this campaign, treating an auth-pass signal as trust directly benefits the operator.
The first anomaly appears in the body. The message declares Content-Type: multipart/form-data with an atypical boundary token such as =-_-XXX_-_<hex>. That MIME subtype belongs to HTTP form uploads, not email. Compliant clients use multipart/alternative or multipart/mixed. A mail body that claims multipart/form-data is anomalous, and body parsers tuned to expected email subtypes can mis-walk it and skip the embedded links. A mail client still renders enough content to display the lure.
The body contains three nearly identical links to the same host. Only the query prefix differs: /qs=r-, /qs=ua-, and /qs=op-. These appear to function as response, unsubscribe-action, and open-pixel beacons, providing per-recipient delivery and engagement telemetry without a third-party tracker. All three use the IPv4-mapped IPv6 literal as the host. When decoded, c0e3:b86d becomes 192.227.184[.]109, a bare virtual server. The body surrounds the malicious links with five to ten scraped legitimate-brand URLs, including CDN image links and email-template references, to camouflage them against naive URL-count heuristics.
The From-line contains further evasions. Brand names include inserted separators, such as T-Mobile//Giveaway, 'United_Healthcare', and PAYMENT///DECLINED. These break exact brand-name matching while remaining readable to a person. In some messages, the local-part begins with a literal IPv4 address (203.0.113.5relief_services@example[.]com), an internal keying artifact that also works as a fingerprint.
Sample Lures
All samples contain attacker-side content with recipient identifiers removed and every URL and domain defanged.
Cloud-storage credential pretext, which was the active front of the campaign in April 2026:
From: "Cloud//Storage" <noreply@mexlarin[.]info>
Subject: April 15: Important notice to secure your data
Return-Path: <bounce@mexlarin[.]info> (SPF / DKIM / DMARC all pass)
CTA (defanged), emitted three times per body:
http[:]//[0000:0000:0000:0000:0000:ffff:c0e3:b86d]/qs=r-afe... -> 192.227.184[.]109
http[:]//[0000:0000:0000:0000:0000:ffff:c0e3:b86d]/qs=ua-...
http[:]//[0000:0000:0000:0000:0000:ffff:c0e3:b86d]/qs=op-...
List-Unsubscribe: <http[:]//mexlarin[.]info/unsubscribe?email=[recipient email]&[0000:0000:0000:0000:0000:ffff:c0e3:b86d]@mexlarin[.]info>
Account-compliance phishing used urgency and the threat of data deletion:
From: "Payment///Overdue" <payment.declined@text-value.oregueirodoallo[.]com>
Subject: LAST CALL: Take action now to avoid data deletion
CTA (defanged): http[:]//[0000:0000:0000:0000:0000:ffff:XXXX:XXXX]/qs=r-<~70-char hex>
Brand-impersonation giveaway, one of 51 display-name variants in the UnitedHealthcare pretext vertical:
From: "UnitedHealthcare//Surprise22" <noreply@tajitsu[.]org>
Subject: Special Access: Free Tote from United Healthcare
CTA (defanged): http[:]//[0000:0000:0000:0000:0000:ffff:334d:64bd]/qs=r-... -> 51.77.100[.]189
Technical Analysis
Two-Layer Architecture: Rotating Senders, Constant Delivery Grammar
The operator's central design choice is the separation of sending from delivery. The sender side rotates aggressively (3,498 addresses, 2,423 domains, per-domain local-part cycling of ten to eighteen fresh addresses in a single day on some domains, a single reused noreply@ on others). The delivery side always uses the same grammar. Every message in every vertical leads to http[:]//[<IPv4-mapped-IPv6 literal>]/qs=r-<~70-char hex>, accompanied by /qs=ua- and /qs=op-. This consistency ties together four populations that would otherwise appear unrelated: aged compromised-domain sends, coined throwaway sends, the UnitedHealthcare-branded vertical (168 senders across 112 domains and 17 TLDs), and the mortgage, insurance, and giveaway brand-pretext clusters. The pretext and sending domain are disposable. The rail remains fixed.
Local-part construction provides its own fingerprint set:
| Local-part template | Example (defanged) |
|---|---|
| Static role address | noreply@ |
| High-entropy paired token | noreply_boxgyvyq.1fxrxxq40aqf@ |
| Pretext-branded | fha-rate-guide@, united_healthcare@, t-mobile//giveaway@, globelife-notice@ |
| IPv4-prefixed | 203.0.113.5relief_services@ |
| Pretext-labelled subdomain | payment.declined@text-value.<apex>, cs-noreply@rosebud.<apex> |
Registration Cohorts: Aged-Compromised vs Purpose-Built
Public WHOIS divides the sending and CTA domains into two populations that correspond to how the operator obtained them. The first cohort is aged, with registrations dating from 2018 to 2023 across several registrars and authentication that aligns cleanly. This is consistent with legitimate small-business domains under the operator's control rather than domains it created. We do not publish that set here. A plausible-looking business name does not prove that the operator registered it, and identifying a compromised victim as infrastructure would be a false accusation.
The second cohort belongs to the operator's own build and is unusually uniform. The coined call-to-action apexes below share one registrar (Namecheap), privacy-withheld or empty registrant orgs, creation dates ranging from weeks to several months before first use, and a tight first-seen cluster in April 2026 corresponding to the campaign's cloud-storage pivot. The .info members return no WHOIS because the .info registry is opaque to most indexers. The operator deliberately chose that reputation blind spot.
| CTA apex (defanged) | Registrar | Created | First seen | Registrant org |
|---|---|---|---|---|
| mexlarin[.]info | none returned | (opaque) | 2026-04-15 | (opaque) |
| kilvexor[.]info | none returned | (opaque) | 2026-04-14 | (opaque) |
| zulmarix[.]info | none returned | (opaque) | 2026-04-14 | (opaque) |
| nexoratio[.]info | none returned | (opaque) | 2026-04-07 | (opaque) |
| infovantara[.]info | none returned | (opaque) | 2026-04-07 | (opaque) |
| zenvatoria[.]info | none returned | (opaque) | 2026-04-07 | (opaque) |
| passtech[.]org | Namecheap | 2025-09-01 | 2026-04-14 | withheld for privacy |
| kelvixor[.]org | Namecheap | 2026-02-09 | 2026-04-10 | withheld for privacy |
| zarnovix[.]org | Namecheap | 2026-02-10 | 2026-04-15 | (empty) |
| funnelpouwer[.]site | Namecheap | 2025-09-09 | 2026-04-17 | withheld for privacy |
Among all operator-coined domains with resolvable WHOIS in this campaign, the registrar was Namecheap almost without exception. The only non-Namecheap records belonged to the aged compromised cohort. That registrar monoculture, together with the privacy-withheld orgs and just-in-time creation dates, provides a stronger cohort signal than any individual domain. A commodity one-domain WHOIS lookup cannot expose this pattern.
The IPv4-Mapped IPv6 Literal, Decoded
Once the structure is understood, reversing the literal is mechanical. The bracketed host is 0000:0000:0000:0000:0000:ffff:XXXX:XXXX. The leading zero groups and the ffff group remain fixed, while the last two 16-bit groups contain the IPv4 address in hex. Each hex group divides into two octets:
[::ffff:c0e3:b86d] -> c0.e3.b8.6d -> 192.227.184[.]109
[::ffff:334d:64bd] -> 33.4d.64.bd -> 51.77.100[.]189
[::ffff:33fe:545a] -> 33.fe.54.5a -> 51.254.84[.]90
The /qs=r- path token accounted for most of the traffic and was a stronger indicator than any individual sending domain. A bracketed ::ffff: host has no legitimate use in ordinary email, while the combined /qs=r- /qs=ua- /qs=op- emission for one host in one body forms a near-unique structural signature.
Backend VPS Distribution and Consecutive-IP Leasing
The decoded backends cluster on low-reputation virtual-server providers rather than mainstream cloud platforms. Reputation coverage was absent, so the provider attribution below is based on backend fingerprints and uses tiers rather than invented precise shares.
| Tier | Providers |
|---|---|
| Dominant | OVH (FR / BHS / UK / CA allocations) |
| Major | ColoCrossing, Hostwinds |
| Moderate | Private Layer, LeaseWeb |
| Minor | VolumeDrive, QuadraNet, ReliableSite |
| Long tail | M247, iWeb, PureVPN, Worldstream, Hetzner, Online SAS |
Several backends are consecutive addresses within the same small block. This suggests that the operator leased /28 or /29 ranges and cycled through each allocation instead of purchasing scattered individual hosts:
| Adjacent backends (defanged) | Signal |
|---|---|
| 199.127.153[.]12, 199.127.153[.]13 | Sequential lease in one range |
| 38.126.208[.]62, 38.126.208[.]65, 38.126.208[.]66 | Three backends in one block |
Domain-Generation Grammar and Decoy CTAs
The coined CTA cluster uses a pronounceable fake-word grammar: three-syllable consonant-vowel chains of seven to nine characters without a dictionary root, often ending in -x, -ix, -or, or -io (mex-la-rin, zul-ma-rix, nex-o-ra-tio, kel-vix-or, zar-no-vix). It also includes the occasional deliberate misspelling (funnelpouwer, from "funnel power"). TLD selection is tiered and cost-driven, with an emphasis on cheap generic new-gTLDs and .info chosen specifically for its indexer-opaque WHOIS.
The toolkit also used two non-standard CTA forms. Synthetic, non-registered .edu strings consisted of twelve consonant-heavy characters plus a six-character suffix on a fake .edu apex that was never registered (rvhrpacykrxo-zzlfux[.]edu). These served as non-resolving decoy or canary links rather than live infrastructure. Keyboard-mash object-storage buckets on AWS S3 and Azure Blob hosted landers under trusted, TLS-backed cloud hostnames. The malicious content resides on the object, while the parent platform is only being abused.
Escalation Over Time
The data shows two changes. First, the adoption of IPv4-mapped IPv6 literal CTAs escalated the operator's reputation evasion. Earlier activity used ESP-style delivery with resolvable, indexable links, whereas the literal form moved the delivery layer entirely outside reputation coverage. Second, the lure surface consolidated. The April 2026 registration cluster of coined .info domains coincides with a move toward cloud-storage and account-compliance credential harvesting on top of the existing mortgage, insurance, and giveaway verticals. The infrastructure grammar remained unchanged as the pretexts narrowed toward credential theft.
Detection Observations
The campaign differs from legitimate mail through its structure rather than any individual reputation lookup. Defenders can use several behavioral signals:
- A bracketed
::ffff:IPv6 literal in a URL authority has no legitimate purpose in consumer email. Normalizing IPv6-literal notation at ingest and then reputation-checking the decoded IPv4 closes the blind spot used by the operator. - The combined appearance of
/qs=r-,/qs=ua-, and/qs=op-links to one host in one body is a near-unique structural marker. - A mail body that declares
Content-Type: multipart/form-datais inherently anomalous and pairs strongly with the IPv6-literal CTA. - Display-name separator injection and IPv4-prefixed local-parts are easy to test for and rare among legitimate senders.
- An IPv6-literal CTA appearing alongside scraped legitimate-brand decoy URLs in the same body is a high-confidence combination.
Authentication does not provide a useful trust signal against this operator. Every message passes SPF, DKIM, and DMARC. Those checks should therefore sit alongside content, sending-pattern, and reputation scoring rather than act as a standalone gate.
Indicators of Compromise
All indicators are defanged and form a curated subset of the verified-malicious set. Aggregate footprint counts describe the operator's infrastructure. The tables below provide a representative slice rather than the full inventory. Compromised legitimate domains are excluded.
Senders
| Value | Role | Notes |
|---|---|---|
noreply@mexlarin[.]info |
Sender | Cloud-storage pivot, coined .info apex |
noreply_qjbsnszl.14i49tq5mhon@pikaduo[.]com |
Sender | High-entropy paired-token local-part |
noreply_jluoiwqw.1nozagq3f57j@superbruno[.]com |
Sender | Throwaway apex, per-day local-part rotation |
noreply_ezwaopto.a9vfiq3chuw@rsynx[.]com |
Sender | Throwaway apex |
| ... | Representative subset; 3,498 sender addresses across 2,423 domains observed |
Domains
| Value | Role | Notes |
|---|---|---|
mexlarin[.]info |
CTA apex | Coined; opaque WHOIS; first seen 2026-04-15 |
zulmarix[.]info |
CTA apex | Coined; opaque WHOIS |
nexoratio[.]info |
CTA apex | Coined; opaque WHOIS |
kilvexor[.]info |
CTA apex | Coined; opaque WHOIS |
infovantara[.]info |
CTA apex | Coined; opaque WHOIS |
zenvatoria[.]info |
CTA apex | Coined; opaque WHOIS |
kelvixor[.]org |
CTA apex | Coined; Namecheap; privacy-withheld |
zarnovix[.]org |
CTA apex | Coined; Namecheap |
passtech[.]org |
CTA apex | Coined; Namecheap |
funnelpouwer[.]site |
CTA apex | Coined ("funnel power"); Namecheap |
pikaduo[.]com |
Sender apex | Throwaway; Namecheap |
superbruno[.]com |
Sender apex | Throwaway; Namecheap |
rsynx[.]com |
Sender apex | Throwaway; Namecheap |
rvhrpacykrxo-zzlfux[.]edu |
Decoy CTA | Synthetic non-registered .edu, non-resolving |
xbkrbthllbfe-ynwcbx[.]edu |
Decoy CTA | Synthetic non-registered .edu, non-resolving |
| ... | Representative subset; 2,423 sender domains observed |
Hosts and IPs
These are decoded IPv4 backends behind the IPv6-literal CTAs. All are bare HTTP endpoints without a hostname or TLS.
| Value | Role | Notes |
|---|---|---|
51.254.84[.]90 |
CTA backend | OVH |
81.17.142[.]20 |
CTA backend | Private Layer (CH) |
194.54.184[.]95 |
CTA backend | Low-reputation EU VPS |
95.211.149[.]201 |
CTA backend | LeaseWeb (NL) |
148.135.79[.]58 |
CTA backend | ReliableSite (US) |
67.222.133[.]28 |
CTA backend | VolumeDrive (US) |
135.148.129[.]4 |
CTA backend | OVH |
67.23.249[.]162 |
CTA backend | QuadraNet (US) |
173.211.87[.]37 |
CTA backend | Hostwinds (US) |
192.227.184[.]109 |
CTA backend | ColoCrossing (US) |
172.245.128[.]215 |
CTA backend | ColoCrossing (US) |
104.168.134[.]200 |
CTA backend | Hostwinds (US) |
199.127.153[.]12 |
CTA backend | Consecutive-lease pair |
199.127.153[.]13 |
CTA backend | Consecutive-lease pair |
51.77.100[.]189 |
CTA backend | OVH; UnitedHealthcare vertical |
| ... | Representative subset; 200+ IPv4 backends across 1,322 IPv6-literal hosts |
URL Pattern
| Value | Role | Notes |
|---|---|---|
http[:]//[0000:0000:0000:0000:0000:ffff:XXXX:XXXX]/qs=r-<~70-char hex> |
CTA | Defining signature; XXXX:XXXX decodes to the backend IPv4 |
http[:]//[::ffff:c0e3:b86d]/qs=r-... |
CTA | Decodes to 192.227.184[.]109 |
http[:]//[::ffff:334d:64bd]/qs=r-... |
CTA | Decodes to 51.77.100[.]189 |
MITRE Fight Fraud Framework (F3) Mapping
This mapping follows the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 reuses ATT&CK T#### identifiers for inherited techniques and adds fraud-native techniques covering the financial-fraud lifecycle. This campaign consists almost entirely of the front-end (resource development, initial access, and stealth), so the mapping is limited to those tactics.
| Tactic | Observed behavior | ID |
|---|---|---|
| Resource Development | Acquire Infrastructure: Virtual Private Server | T1583.003 |
| Resource Development | Acquire Infrastructure: Domains | T1583.001 |
| Resource Development | Compromise Infrastructure / Accounts | T1584 / T1586 |
| Resource Development | Acquire Infrastructure: Web Services (cloud buckets) | T1583.006 |
| Initial Access | Phishing | T1566 |
| Initial Access | Impersonation | T1656 |
| Stealth | Obfuscated Indicators (IPv4-mapped IPv6 literal CTA) | T1027 |
| Stealth | Impair Content Defenses (multipart/form-data body, decoy URLs, display-name injection) | fraud-native |
| Stealth | Infrastructure Rotation (snowshoe / burn-and-rotate) | fraud-native |
Conclusion
A notation problem became a reputation problem. The operator's hosting was not sophisticated: the servers were cheap and disposable, while the sending domains burned by the thousand. The delivery layer survived because scanners did not normalize its URL format. Defenders can remove the operator's single load-bearing advantage by decoding IPv4-mapped IPv6 literals at ingest and reputation-checking the underlying IPv4. The next iteration will likely use another unnormalized encoding because the sending side is already designed to rotate faster than any blocklist can follow.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.