Hackers are employing innovative tactics to bypass email security by using QR codes without embedding image files. These codes, crafted from email markup, direct unsuspecting recipients to phishing sites while circumventing traditional security checks that rely on image detection.
Shift to Mobile Devices
By utilizing QR codes, attackers are transitioning their phishing attempts from monitored workstations to mobile devices. The QR scan obscures the final destination until it is opened on the phone, potentially leading users to pages that harvest login credentials, session tokens, or payment information, or even trigger malicious downloads.
PhishU Framework analysts discovered this technique after analyzing a type of phishing called ‘quishing,’ where QR patterns are embedded directly in the email body. This reflects an evolution in attacker strategies as security systems improve at detecting conventional threats.
Innovative Techniques in Phishing
According to a report by PhishU Framework shared with Cyber Security News, even with remote images disabled, the QR code can still be displayed. The report highlights a vulnerability, not an invincible attack; systems that visually render the entire email can still detect these codes.
Traditional QR phishing schemes involved bitmaps within attachments or email body text, allowing secure email gateways to decode and inspect the link. The new approach eliminates this initial step by crafting QR codes from HTML tables or text-like blocks, rendering them directly in the email layout.
Enhancing Email Security
For security teams, the key takeaway is to avoid assuming that the absence of an image means no QR code is present. It is crucial to visually render suspicious HTML, examine for QR patterns, and verify any extracted destination before processing the email.
Detection systems should also be on the lookout for dense grids of cells, repeated color patterns, or character blocks in fixed-width arrangements. While these indicators aren’t inherently malicious, they warrant closer examination of emails that deviate from standard business communications.
Administrators should maintain remote-image blocking but not rely solely on it for defense against quishing. Testing email paths with authorized simulations can confirm detection of markup-constructed codes, and link protection should be reviewed post-delivery.
Recommendations for Employees
Employees are advised to adopt behavioral defenses: do not scan unsolicited QR codes based on perceived urgency. Always verify requests through established channels, check decoded addresses before visiting them, and use phishing-resistant authentication methods whenever possible.
The threat is heightened when attackers use compromised mailboxes, as they can make phishing attempts appear legitimate. This development serves as a reminder that email security must assess a message’s behavior, not just its content.
Ultimately, QR codes created from markup remain visible to human users, so layered filtering, thorough inspection, and user education are the most effective methods to prevent accounts from being compromised through phishing.
