The Contract You Didn't Request Has a QR Code You Shouldn't Scan
ID: 3f8aae2f-4091-577e-b41e-808afbfc7b18
STIX ID: report--3f8aae2f-4091-577e-b41e-808afbfc7b18
Feed Name: IRONSCALES
A targeted QR-code phishing campaign delivered a personalized credential-harvesting URL embedded as a QR image inside a PDF attachment sent from a recently registered domain; each QR code contained the recipient's email (base64) in the URL fragment to pre-fill and legitimize the credential prompt. The message body was blank to evade text-based detectors, SPF/DKIM/DMARC were absent or failed, the sending IP was a disposable ColoCrossing host, and the landing site used Cloudflare. IRONSCALES flagged the attachment malicious at 89% confidence and quarantined it within two seconds; the report maps the attack to MITRE techniques (spearphishing attachment, user execution via link, masquerading) and recommends improving QR decoding in email security, enforcing DMARC, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
