(QR) Coding My Way Out of Here: C2 in Browser Isolation Environments
ID: 9ee270fa-058c-5201-95ae-aa441bc8aa10
STIX ID: report--9ee270fa-058c-5201-95ae-aa441bc8aa10
Feed Name: Google Cloud Threat Intelligence
Mandiant describes a technique that can circumvent types of browser isolation (remote, on‑premises, and local) by using machine-readable QR codes to convey commands from an attacker-controlled server to a victim device, effectively enabling command-and-control despite isolation that normally only streams rendered pixels to the client. The post explains browser isolation types, why typical HTTP-based C2 is blocked by isolation, and demonstrates how QR-based channels can be abused to restore C2 capability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
