Quick-response codes, more commonly known as QR codes, have been widely used since at least the year 2000 when the technology became an international standard.

With a QR code, a seemingly unintelligible set of pixels inside of a square box is somehow able to be understood by a QR code reader as a web address. With the pervasiveness of smartphone cameras enabled as QR code readers in recent years, QR codes have become ubiquitous in the modern world as a convenient way to link to websites.

While a QR code can be a convenience, it can also be a risk according to security vendor Trustwave. In fact, QR codes can be a pathway to exploitation and malware, in an attack type that Trustwave refers to as qishing (ed. note: also spelled from other sources as quishing).

In a new report, Trustwave warns that it has noticed an uptick in 2023 of malicious QR code qishing attacks. Karl Sigler, senior security research manager at Trustwave SpiderLabs, told SDxCentral that while QR code-based phishing has been around for a while, QR codes haven't always had wide adoption.

"The need for contactless menus and other info during the pandemic brought QR use into wide acceptance," Sigler said. "So, we’re definitely seeing an uptick in malicious QR use.”

Qishing attacks take aim at multifactor authentication notifications

While qishing attacks can occur wherever QR codes are used, Trustwave has observed an uptick in a particularly devious new attack campaign.

"What’s new in the campaign is a combination of QR codes embedded in regular phishing emails and credential-capture attacks based on fake MFA [multifactor authentication] prompts, which is another technology seeing wider adoption due to shifts in remote work,” Sigler said.

With MFA prompts, a user can potentially get a message via SMS, a secure app, or via email. The qishing attacks observed by Trustwave send a QR code via email, which the victim is encouraged to scan in order to get access to the MFA-protected service. The reality is that the QR code does not direct the victim to the destination the user expects and instead sends them to a phishing page where further credential harvesting and malware can potentially be deployed to exploit victims.

Trustwave has observed the multifactor qishing attacks in some cases as targeting specific organizations with customized templates that are designed to look like legitimate verification requests. The destination phishing page is also highly customized to appear as a legitimate sign-on page for the targeted organization.

The PDF qishing connection and how attackers evade detection

Trustwave is also seeing a rise in the use of PDFs with malicious QR codes.

The malicious QR code contains a shortened URL that is then redirected to the attacker's phishing page. The use of the QR code with the shortened URL is able in some cases to bypass some antispam filters.

Another common technique that Trustwave is seeing with qishing is using Microsoft bing.com search result links as a way to evade malware address filters. The Bing search result leads users to a page that will redirect a victim to the malicious address.

How to defend against qishing

With all the network defenses that organizations have in place, including firewall and web address filtering, qishing is still able to get through.

Sigler noted that most security controls around phishing attacks, such as secure email gateways and mail server antivirus scans, occur before the email lands in a victim’s inbox. As such, if a user clicks on or scans a malicious URL, it may already be too late to prevent compromise.

"While network URL filtering and antimalware will help with known malware and malicious web servers, it doesn’t help in many of these cases [of qishing]; for instance, where the user is directed to provide credentials to an attacker," Sigler said.

So what should users do? For one, Sigler suggests that organizations be wary of QR codes in certain situations.

"I can’t think of a single valid reason a QR code should be embedded into an email outside of potentially an email signature," Sigler said. "If you see a QR code in an email, do not scan it. This is especially true for emails where the sender is specifically asking you to scan the code."