QR Phishing. Fact or Fiction?
ID: 1d32f114-1b43-5af8-8b11-e3e50ed6d026
STIX ID: report--1d32f114-1b43-5af8-8b11-e3e50ed6d026
Feed Name: Pen Test Partners Blog
The report analyzes “Quishing” (QR code phishing), where attackers embed base64 QR codes in emails to evade URL scanning and entice users to scan on mobile devices with weaker defenses, then leverage AiTM proxies to capture M365 credentials and session tokens for broader access (e.g., VPN). It critiques widely cited volume statistics, notes that while vendors claim detection capabilities the technical controls remain immature, and recommends prioritizing user awareness and training while calibrating risk relative to traditional URL phishing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
