Hackers Using Malicious Imageless QR Codes to Render Phishing Attack Via HTML Table
ID: 91ac7262-6000-5cc8-b45c-0cef48c9db72
STIX ID: report--91ac7262-6000-5cc8-b45c-0cef48c9db72
Feed Name: cybersecurityNews.com
A recent phishing campaign (observed Dec 22–26) abuses HTML tables to render QR codes from many tiny black/white cells instead of embedding image files; the technique bypasses QR/image inspection in secure email gateways and redirects victims to subdomains of lidoustoo.click, often including the recipient's domain in the URL to increase credibility. The report highlights detection gaps and recommends DOM-aware analysis, treating dense table grids as potential QR renderings, and user training to avoid scanning unsolicited QR codes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
