HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning
ID: 93629ddc-f741-5e74-8320-e819e826feee
STIX ID: report--93629ddc-f741-5e74-8320-e819e826feee
Feed Name: GBHackers
Researchers observed a quishing (QR-phishing) campaign that renders scannable QR codes via HTML tables and text in email bodies to bypass image-based email scanners; victims are lured to credential-harvesting pages (notably using personalized subdomains under lidoustoo.click). The technique exploits a structural blind spot in Secure Email Gateways where no image object exists to decode, and defenders are advised to render suspicious HTML in isolation, inspect visuals/screenshots for QR payloads, and flag dense black/white table grids, unusual bgcolor usage, or QR-themed language in emails.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
