New Delhi: Cyber attackers are increasingly using split and nested QR codes in a new wave of phishing attacks, known as “Quishing,” to bypass traditional detection systems, according to Barracuda Networks’ recent threat report.
Barracuda’s threat analysts uncovered two innovative techniques used by phishing gangs to evade detection. These methods involve splitting a malicious QR code into two separate images to confuse scanning systems, or nesting a malicious QR code inside a legitimate one, making it harder for security tools to identify the threat.
Quishing, a form of phishing, relies on QR codes embedded with malicious links. When scanned, these QR codes redirect victims to fake websites designed to steal sensitive information, such as login credentials. Despite appearing legitimate, the codes lead to fraudulent destinations.
Split QR Codes
In one example, the Gabagool phishing group used split QR codes in a fake Microsoft ‘password reset’ scam. The attackers split the QR code into two separate images, embedding them close together in a phishing email.
To the human eye, the images appeared as a single QR code. However, traditional email security solutions recognised them as two distinct and harmless images. When scanned, the malicious QR code directs the victim to a phishing website designed to steal credentials.
Nested QR Codes
The Tycoon phishing-as-a-service (PhaaS) group employed a more sophisticated method by nesting a malicious QR code around a legitimate one. The outer QR code directed victims to a harmful URL, while the inner QR code led to Google. Attackers use this tactic to make it harder for security systems to detect the threat, as the results appear ambiguous.
How to Defend Against Quishing
Barracuda experts recommend multi-layered email protection that integrates AI capabilities to detect evolving threats. In addition to security awareness training, multifactor authentication and robust spam filters, businesses should use systems capable of identifying and inspecting QR codes directly. This ensuring malicious content is flagged before reaching users.
(Image for representational purpose)
