logo

Phishing on the Edge of the Web and Mobile Using QR Codes

ID: a206d60b-79d7-518d-81b5-b718508eae75

STIX ID: report--a206d60b-79d7-518d-81b5-b718508eae75

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2026-02-13

Date Updated: 2026-04-28

Author: Diva-Oriane Marty, Shehroze Farooqi and Alex Starov

...
...

This Unit 42 report examines the growing misuse of QR codes for malicious purposes: attackers leverage QR-code shorteners to hide destinations, in‑app deep links to trigger account logins or app actions (enabling messenger account takeovers and payment fraud), and QR-linked direct APK downloads to distribute malicious Android apps. Telemetry shows thousands of malicious QR detections daily, targeted campaigns (including Signal targeting in the Russia–Ukraine context), multiple observed attack scenarios (financial fraud, contact/calendar poisoning, device linking), and numerous IOCs provided for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.