Why QR code attacks are the spawn of the Devil

When it comes to phishing, QR codes have quickly become the new malicious link or attachment. Their use, however, reaches out from the digital realm into the real world and thatโ€™s what makes them so dangerous.

The most extreme example of this is the recent case in Switzerland where threat actors are actually sending targeted phishing mails to potential victims, complete with QR code payloads, using snail mail.

Yes, you read that right, good old-fashioned printed letters.

Chris Fuller, Senior Director of Technical Operations at Obsidian Security, said that โ€œpeople have started to become aware of email phishing scams and so this new method of using physical mail is a clever method used by attackers to fool unsuspecting victimsโ€.

Of course, once that code is scanned it takes the victim to a download that is actually malware. More straightforward fraud is accomplished by QR code attackers using the sticker-based approach of covering real codes on parking meters with ones leading to scam sites that grab your card details and cash.

Latest QR code attack research

Now, new research by Jeason Schultz at Cisco Talos has taken a deep dive into just how big of a problem malicious QR codes are.

The research, published 20 November,ย took an analytical approach to the issue and discovered that an astonishing 60% of all emails that contain a QR code are, surprise surprise, spam.

The research surmised that QR codes are disproportionately effective at bypassing anti-spam filters because most filters aren’t designed to recognise that a QR code is present in an image and decode the QR code.

And thatโ€™s where the problem starts, but doesnโ€™t end, for users.

As Iโ€™ve already explained, scanning unknown QR codes is analogous to clicking an unknown link or opening an unsolicited attachment or document. Cisco Talos said that the most common malicious QR codes, however, tend to impersonate multifactor authentication requests used for phishing user credentials.

Thereโ€™s even a danger of getting caught up in a malicious visual puzzle that is a result of the use of QR code art where the data points of the code are blended into an image that, helpfully, doesnโ€™t look anything like a QR code at all.

How to defend yourself against QR code attacks

So, we can all hopefully agree that QR codes are the spawn of the devil, but how can we stop our souls from being sold to the dude in red leggings?

The simple solution is to treat QR codes as you would any other unknown link: with suspicion. But although simple, it’s hard to turn into reality,

That’s because the codes are everywhere, from restaurant menus to retail packaging and beyond; they have become part of our everyday experience. This familiarity breeds contempt, for the user by the attacker, and it works.

How can I put this politely? Donโ€™t. Scan. QR Codes. At. All.

Iโ€™m serious, sort of. What I should say is only scan codes after using an abundance of caution. Better still, use one of the many QR code decoder apps out there which will reveal the data encoded within.

Even using your iPhone camera, for example, will give you the URL address when itโ€™s hovering over the code and before you click it.

And, as Schultz sagely reminds us: โ€œNever enter your username and password into an unknown site. It is better to navigate directly to anywhere you wish to login, rather than clicking on a URL presented to you from an unknown third party.โ€

Recent security articles

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.