Belfius Bank App searches for UAT & Staging servers in production
Belfius did not respond to a request for comment prior to publication.
In the previous parts of this series, we documented how a mobile endpoint can be isolated via RRC downgrade attacks and how the trust engine of a macOS workstation can be surgically blinded by a fraudulent root certificate. This article shifts the forensic lens to the banking application running on it.
The immediate trigger for this analysis is the remarkable discovery of links to test servers in swcutil_show.txt, a file originating from Apple's own diagnostic archive.
| # | swcutil_show.txt |
Shows Shared Web Credentials (AASA). Manages which apps are authorized to open or claim specific web domains. |
|---|
swcutil_show.txt > Belfius
Plaintext -------------------------------------------------------------------------------- Service: applinks App ID: 83J363HHQD.be.belfius.BelfiusDirectMobile App Version: 221010921.0 App PI:{ v = 0, t = 0x8, u = 0x664, db = E8A640A3-8E0A-441C-8B12-414AFD3CB5D0, {length = 8, bytes = 0x6406000000000000} } Domain: uat-staging.belfius.be User Approval: unspecified Site/Fmwk Approval: unspecified Flags: Last Checked: 2022-04-29 18:44:16 +0000 Error: Error Domain=SWCErrorDomain Code=7 "SWCERR00301 Timeout -- {"cause":"context deadline exceeded (Client.Timeout exceeded while awaiting headers)"}" UserInfo={Line=274, Function=-[SWCDownloader URLSession:dataTask:didReceiveResponse:completionHandler:], NSDebugDescription=SWCERR00301 Timeout -- {"cause":"context deadline exceeded (Client.Timeout exceeded while awaiting headers)"}, UnderlyingError=Error Domain=HTTP Code=404 "(null)" UserInfo={Line=274, Function=-[SWCDownloader URLSession:dataTask:didReceiveResponse:completionHandler:]}} Retries: 8 -------------------------------------------------------------------------------- Service: applinks App ID: 83J363HHQD.be.belfius.BelfiusDirectMobile App Version: 221010921.0 App PI: { v = 0, t = 0x8, u = 0x664, db = E8A640A3-8E0A-441C-8B12-414AFD3CB5D0, {length = 8, bytes = 0x6406000000000000} } Domain: uat-www.belfius.be User Approval: unspecified Site/Fmwk Approval: denied Flags: Last Checked: 2022-05-01 11:43:21 +0000 Next Check: 2022-05-06 11:29:51 +0000 -------------------------------------------------------------------------------- Service: applinks App ID: 83J363HHQD.be.belfius.BelfiusDirectMobile App Version: 221010921.0 App PI: { v = 0, t = 0x8, u = 0x664, db = E8A640A3-8E0A-441C-8B12-414AFD3CB5D0, {length = 8, bytes = 0x6406000000000000} } Domain: gtu-www.belfius.be User Approval: unspecified Site/Fmwk Approval: denied Flags: Last Checked: 2022-05-01 11:43:21 +0000 Next Check: 2022-05-06 11:29:51 +0000 -------------------------------------------------------------------------------- Service: applinks App ID: 83J363HHQD.be.belfius.BelfiusDirectMobile App Version: 221010921.0 App PI: { v = 0, t = 0x8, u = 0x664, db = E8A640A3-8E0A-441C-8B12-414AFD3CB5D0, {length = 8, bytes = 0x6406000000000000} } Domain: staging.belfius.be User Approval: unspecified Site/Fmwk Approval: unspecified Flags: Last Checked: 2022-04-29 18:44:16 +0000 Error: Error Domain=SWCErrorDomain Code=7 "SWCERR00301 Timeout -- {"cause":"context deadline exceeded (Client.Timeout exceeded while awaiting headers)"}" UserInfo={Line=274, Function=-[SWCDownloader URLSession:dataTask:didReceiveResponse:completionHandler:], NSDebugDescription=SWCERR00301 Timeout -- {"cause":"context deadline exceeded (Client.Timeout exceeded while awaiting headers)"}, UnderlyingError=Error Domain=HTTP Code=404 "(null)" UserInfo={Line=274, Function=-[SWCDownloader URLSession:dataTask:didReceiveResponse:completionHandler:]}} Retries: 8 -------------------------------------------------------------------------------- Service: applinks App ID: 83J363HHQD.be.belfius.BelfiusDirectMobile App Version: 221010921.0 App PI: { v = 0, t = 0x8, u = 0x664, db = E8A640A3-8E0A-441C-8B12-414AFD3CB5D0, {length = 8, bytes = 0x6406000000000000} } Domain: www.belfius.be Patterns: {"/":"/common/??/fw/generic/*"} User Approval: unspecified Site/Fmwk Approval: approved Flags: Last Checked: 2022-05-01 11:43:21 +0000 Next Check: 2022-05-06 11:29:51 +0000 --------------------------------------------------------------------------------
4 Non-production domains?
One production domain. The production domain was approved. The test domains were denied or received a timeout — but not before iOS had already tried to reach them.
What These Domains Mean
For context: uat-staging, staging, uat-www, and gtu-www are not ambiguous subdomain names. Within software development and banking infrastructure, these prefixes have a universally understood meaning:
UAT User Acceptance Testing: A controlled pre-production environment used for internal validation by Belfius employees before a release is approved.
Staging: A mirror of the production environment, used for the very final integration tests.
They are not indexed by DNS resolvers accessible to the general public. Consumer applications have no business being here.
If a normal iPhone on a normal network tries to call a non-existent number, this happens:
- The iPhone asks the provider (DNS): "What is the IP address of uat-staging.belfius.be?"
- The provider looks in the public phone book and immediately says: "This domain does not exist" (technically: an NXDOMAIN or SWCERR00304 DNS Error).
- This takes less than a fraction of a second. There is no timeout, because the answer is immediately "No". But in this specific case, something completely different happened: The manipulated network environment did not say "No", but did return an IP address to the iPhone.
How can an iPhone get an IP address for a server that does not exist on the public internet? Because the iPhone was not on the public internet.
The Timeout Anomaly
This distinction is important. A DNS error means the domain is unknown. A timeout means the domain was found, but the server did not respond in time. These are not equivalent outcomes.
The Scale Problem
With 1.5 million active Belfius users at the time, a structural error in the public app would have led to millions of unintended pings (8 attempts per device) to the internal test servers. Such a load would inevitably have crashed this pre-production environment.
Since a server outage did not occur and an emergency patch for the app was never released, this points to a highly targeted anomaly.
The Institution's Response
A formal GDPR access request was submitted to Belfius to request the logs and data surrounding these and other observations. This was necessary to trace the origins of the abuses, initially without pointing fingers at the bank.
Instead, the bank chooses a blind denial and eventually even open threats.
The request was initially signed by an identifiable representative of the GDPR operations team but when the bank gets into a tight spot - they switch halfway through the email thread to a certain 'Jérémie', apparently without a last name. Jérémie X believes he does not need to answer further because the request might be AI-generated. The fear of GEN AI is real?
The bank stated that the user's identity did not exist and that no audit trail was available. This position was maintained even after it was pointed out that unauthorized root certificates from their own IT partner had ended up on the victim's personal devices. The bank's subsequent reaction was extremely defensive: the victim was suddenly portrayed as the perpetrator and then even intimidated.
BELFIUS RESPONSE:
"I therefore urgently request that you cease this unlawful behavior immediately. Otherwise, the Bank will be forced to take further legal action, including criminal steps. I assume you will want to avoid the costs and unpleasantness this could bring you."
That is an unmistakable threat! Although the legal process remains undiscussed here, the formal response of the institution is striking. Where a technical explanation for the log data (such as a handled release error, a lost MDM profile, or IPsec routing errors) would have been obvious, the bank dismissed the objective findings and warned of further consequences.
This formal rejection contrasts with the fact that in the period 2020-2023, loans were taken out in the name and behind the back of the victim. Prior complaints were also never investigated or taken seriously by the bank. In this case, the raw log files and cryptography outweigh formal denials.
Claude AI after all?
To provide this article with further (un)necessary substantiation that 'only' comes from Claude AI, we asked the most advanced AI on the market to make an analysis based on the system diagnostics coming directly from Apple, and compare these with the hypotheses raised.
ATTENTION - The content below is generated by AI.
What the log files add to the article
1. DNS resolver 172.26.0.2 — the key to the UAT timeout
In buffer c7 (22:38–23:40 CEST) it literally states:
SWCERR00304 DNS error — {"cause":"dial tcp: lookup maps.google.iq
on 172.26.0.2:53: no such host"}
The device uses 172.26.0.2:53 as a DNS resolver — a private RFC-1918 address that never appears as a DNS server on a normal consumer network. The own WiFi adapter (en0) has IP 192.168.68.105, which is a regular home router. But the SWCERR lookup runs via a different path. This confirms the argument from the article: the UAT timeouts are not regular DNS-NXDOMAIN errors, but slow responses via an injected internal network that did know the test domains — and failed for public domains.
2. be.belfius.BelfiusDirectMobile in the TCCD authorization list with kTCCSUbiquity
In LiveData there is a TCCD access request (TCC = the iOS privacy/permission database) where the service kTCCSUbiquity is requested — which is iCloud Drive access. The clients list in that same request contains as the first entry:
[0] = "be.belfius.BelfiusDirectMobile"
Followed by: Keynote, Mail, Numbers, Pages, iBooks, GarageBand, MobileSMS, Safari, Shortcuts, Google Drive, host.exp.Exponent, WhatsApp, Zoom.
A banking app in a TCCD list for iCloud Drive synchronization Ubiquity is not normally expected. The auth_value=2 (access granted) and result=true are particularly relevant.
3. host.exp.Exponent (Expo Go) next to Belfius in the same authorization chain
In c8 the following chain of processes/entities appears:
AccountAuthenticationDialog → host.exp.Exponent → ctkuiq →
ScreenTimeWidgetAppl → FontInstallView → be.ING.OneApp →
AppSSOUIq → microsoft.azureauthenticator → DiagnosticsExt →
Google Chrome
These are in one context: an authentication dialog, the Expo Go runtime host.exp.Exponent, a CTK operation ctkuiq, a font installation view (typical for MDM profiles pushing fonts), the ING app, and Microsoft's SSO authenticator. This is not a normal user session — this is an authentication chain pointing to a shared identity platform between apps.
4. be.ING.OneApp PID 2304 active during the CTK peak
In cb (11:28–11:51 CEST — the buffer with the highest CTK activity in the entire log) be.ING.OneApp is demonstrably active as a running process application. It requests a FinishTask background assertion with the PreventThrottleDown flag, meaning it actively wants to complete network transactions while in the background. This coincides with the ctk-tokens activity in the same buffer.
5. Microsoft Authenticator microsoft.azureauthenticator active in all buffers
Present in c2 up to LiveData — every buffer. This is the Microsoft Authenticator app. Combined with **AppSSOUI** (Single Sign-On extension) and the ING app, this suggests a shared identity platform. Relevant to the article as it extends the authentication chain beyond just Belfius.
6. MDMRMu in DNS CNAME chains (c2 to c5)
In the DNS logs (c2, c3, c4, c5), CNAME chains repeatedly appear via pdp_ip0 (the mobile data interface) where one of the A-record labels is named MDMRMu. This is an internally labeled DNS record that is looked up via the mobile data bearer — possibly an MDM-related endpoint label that travels along in the DNS response structure.
In summary: The logs confirm (a) that the UAT timeouts ran via a non-standard internal DNS resolver at 172.26.0.2, (b) that Belfius Direct Mobile is listed as the first client in an iCloud synchronization permission request, (c) that Expo Go, ING, Microsoft SSO, and a font installation view co-occur in one authentication chain in c8, and (d) that ING is actively executing network transactions during the CTK peak in cb. None of these findings is conclusive on its own, but as a corpus, they significantly strengthen the thesis of a non-standard application configuration on this specific device.
Belfius did not respond to a request for comment prior to publication.