QR codes are being used in phishing attacks against US institutions

A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
(Image credit: weerapatkiatdumrong / Getty Images)

Cybersecurity researchers from Cofense recently observed a large-scale phishing campaign that targeted, among others, a “major” U.S. energy company. 

What makes this campaign unique is the fact that the attackers used QR codes to bypass email security solutions at scale, which is not something we see very often.

Phishing is a key attack vector, with nine in ten cyberattacks starting through this communications channel. However, email security solutions have become quite good at filtering abusive content over the years, which is why the majority of phishing emails that carry either malicious links, or attachments, never usually make it to victims’ inboxes.

Creative solutions

This has prompted some threat actors to get creative, and use innovative methods to sneak past security gateways. One such method is the deployment of QR codes, which redirect the victim to a phishing site. 

As the QR codes come in the form of a .PNG or .JPG, they’re able to evade detections. Another unique aspect of this particular campaign is its scale, with thousands of emails being sent out - again a rare sight. 

Cofense says that the attackers distributed roughly 1,000 emails, with almost a third (29%) targeting a single, unnamed but prominent U.S. energy company. Other emails were sent to companies operating in the manufacturing (15%), insurance (9%), technology (7%), and financial services (6%) sectors. 

The QR codes redirected the victims to a malicious landing page resembling a Microsoft 365 login page, with the obvious goal of stealing the login credentials for the service. In the email, the victims were told they needed to update their account settings within three days, adding a false sense of urgency. 

The good news is that victims still need to take action to get compromised, which shouldn't be easy for well-trained employees. However, recent reports have shown that many workers are still falling for fake and dangerous emails. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
QR Code
Hackers are targeting Signal with new QR code-linked cyberattack
Fraude en ligne phishing
Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Someone checking their credit card details online.
Hackers use CAPTCHA scam in PDF files on Webflow CDN to get past security systems
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
Latest in Pro
Group of people meeting
Inflexible work policies are pushing tech workers to quit
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
An image of network security icons for a network encircling a digital blue earth.
Why multi-CDNs are going to shake up 2025
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Latest in News
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently making a major announcement about the MCU, and I think we're getting an official Avengers: Doomsday cast reveal
Nintendo Switch Lite
Forget the Nintendo Switch 2, the original Switch is getting one last hurrah in a surprise Nintendo Direct tomorrow
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
Samsung Galaxy S25 Edge colors seemingly revealed in new video, and there’s another sign of an imminent launch
Image of Naoe in AC Shadows
Assassin's Creed Shadows best graphics settings for PS5, PS5 Pro, and Xbox Series X
Promotional image for Malcolm in the Middle featuring the original cast playing golf
Malcolm in the Middle's Disney+ revival gets underway as the series finds its cast – here's which characters are returning
Group of people meeting
Inflexible work policies are pushing tech workers to quit