Beware this new-ish attacker tactic: QR code attacks
ID: 911ba32e-9bd0-5215-8b76-87ecc6326eac
STIX ID: report--911ba32e-9bd0-5215-8b76-87ecc6326eac
Feed Name: Expel Blog
This report describes an observed increase in "qishing"—QR-code-based credential-harvesting attacks that lead victims to malicious login pages and often evade endpoint detection because victims scan codes with personal devices. The authors outline triage and analysis steps (decode QR with ZXing, sandbox the landing page, use dummy credentials to identify credential exfiltration domains, search network telemetry), provide examples of malicious domains and screenshots, and note defensive actions such as prioritizing alerts and a YARA rule to detect grayscale PNG QR attachments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
