logo

HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning

ID: 93629ddc-f741-5e74-8320-e819e826feee

STIX ID: report--93629ddc-f741-5e74-8320-e819e826feee

Feed Name: GBHackers

Threat Score
60/100

Date Published: 2026-09-03

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

Researchers observed a quishing (QR-phishing) campaign that renders scannable QR codes via HTML tables and text in email bodies to bypass image-based email scanners; victims are lured to credential-harvesting pages (notably using personalized subdomains under lidoustoo.click). The technique exploits a structural blind spot in Secure Email Gateways where no image object exists to decode, and defenders are advised to render suspicious HTML in isolation, inspect visuals/screenshots for QR payloads, and flag dense black/white table grids, unusual bgcolor usage, or QR-themed language in emails.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.