logo

Beware this new-ish attacker tactic: QR code attacks

ID: 911ba32e-9bd0-5215-8b76-87ecc6326eac

STIX ID: report--911ba32e-9bd0-5215-8b76-87ecc6326eac

Feed Name: Expel Blog

Threat Score
55/100

Date Published: 2023-12-07

Date Updated: 2026-04-27

Author: Hiranya Mir; Milo Romano

...
...

This report describes an observed increase in "qishing"—QR-code-based credential-harvesting attacks that lead victims to malicious login pages and often evade endpoint detection because victims scan codes with personal devices. The authors outline triage and analysis steps (decode QR with ZXing, sandbox the landing page, use dummy credentials to identify credential exfiltration domains, search network telemetry), provide examples of malicious domains and screenshots, and note defensive actions such as prioritizing alerts and a YARA rule to detect grayscale PNG QR attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.