logo

Distribution of Qshing Emails Disguised as Payslips

ID: 4c7e7582-e2d3-5b2f-8ff7-5284cad682db

STIX ID: report--4c7e7582-e2d3-5b2f-8ff7-5284cad682db

Feed Name: ASEC

Threat Score
50/100

Date Published: 2024-02-02

Date Updated: 2026-04-26

Author: gygy0101

...
...

AhnLab ASEC identified a Qshing campaign impersonating the PRC Ministry of Finance where phishing emails containing QR codes redirect victims to mobile-only phishing pages that prompt for personal details and financial information. The report details email spoofing techniques, browser-width based redirection to mobile pages, the user flow that harvests names, ID numbers, credit card data and credentials, and lists associated URLs/FQDNs as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.