logo

QR codes bypass browser isolation for malicious C2 communication

ID: fb8b47e8-2a26-53e7-bf2e-b1f7642aa12a

STIX ID: report--fb8b47e8-2a26-53e7-bf2e-b1f7642aa12a

Feed Name: Bleeping Computer

Threat Score
40/100

Date Published: 2024-12-08

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Mandiant demonstrated a proof-of-concept C2 evasion that encodes commands into QR codes displayed by remote/isolated browsers so the visual pixel stream can return to an infected host which captures and decodes the QR to receive instructions; the technique (shown with Cobalt Strike) is feasible but low-bandwidth, has latency and reliability limits, and may be mitigated by additional security controls and heuristics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.