A phishing campaign with QR codes rendered using an HTML table, (Wed, Jan 7th)
ID: e9d9d453-dbbd-59e0-aa5b-cadb735bcfb5
STIX ID: report--e9d9d453-dbbd-59e0-aa5b-cadb735bcfb5
Feed Name: SANS ISC Diary
Threat Score
This report describes a short phishing campaign (sent Dec 22–26) that evaded email QR-code detection by rendering QR codes using HTML tables (black/white table cells) instead of images. All observed QR codes resolved to subdomains of lidoustoo.click with a consistent URL structure, and the post includes sample HTML, the URL pattern, and commentary on the implications for defensive controls and user awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
