logo

Hungarian Bank, Nepali Domain, Broken Encoding: How a K&H Bank Phishing Kit Exposed Itself

ID: f2c83fe9-9d28-50da-9539-9f17547da1d1

STIX ID: report--f2c83fe9-9d28-50da-9539-9f17547da1d1

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-23

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A high-severity credential-phishing campaign impersonated Hungary's K&H Bank by using the display name "K&H Bank" while sending from [email protected] (Nepal); the message hotlinked the real kh.hu favicon, pointed victims to ecstechs.net for credential harvesting, carried a valid DKIM signature despite SPF="none", and exhibited a character encoding mismatch (mojibake) that revealed the phishing kit — IRONSCALES flagged and quarantined the email and the report enumerates IOCs and MITRE mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.