Quick response (QR) codes, initially designed to track car parts in the early 90s and popularized during the COVID-19 pandemic when many restaurants turned to electronic menus, have unfortunately become a tool for cybercriminals to exploit and for scammers to hide phishing links for stealing personal information.
These QR code phishing attacks, also known as quishing or qishing, work by directing victims who scan the QR code (typically using their smartphone) to malicious sites or links, according to phishing detection provider Netcraft.
The Federal Trade Commission (FTC) recently issued a consumer alert in response to the growing number of reports of QR code scams.
“A scammer’s QR code could take you to a spoofed site that looks real but isn’t. And if you log in to the spoofed site, the scammers could steal any information you enter. Or the QR code could install malware that steals your information before you realize it,” the agency said.
A recent report from Trustwave also showed that QR code phishing attacks are on the rise. “What’s new in the campaign is a combination of QR codes embedded in regular phishing emails and credential-capture attacks based on fake MFA [multifactor authentication] prompts, which is another technology seeing wider adoption due to shifts in remote work,” Karl Sigler, senior security research manager at Trustwave SpiderLabs, told SDxCentral in an earlier interview.
Why cybercriminals use QR codes for phishingNetcraft pointed out in a blog post that despite more people knowing how to spot suspicious-looking links in phishing emails, there is typically no user-accessible way to check the destination before scanning the QR code.
QR codes offer several advantages for cybercriminals, including:
- Concealing URLs: QR codes provide an effective mechanism to hide suspicious URLs, countering the growing user skepticism toward questionable links.
- Bypassing corporate controls: When users receive a QR-based phishing email on their work computer, they typically will scan the QR code using their personal devices like their phones, which may have different (often lesser) built-in security from a company computer or phone.
- Evading security tools: Many security systems can't scan images, making QR-based phishing emails harder to detect.
To use QR codes securely, the FTC suggests the following precautions:
- Exercise caution with QR codes found in unusual locations. You should inspect the URL for misspellings or a switched letter before you open it when seeing a QR code in an unexpected place. According to this post from QR Planet, you can download a QR code scanner app or use your iPhone's native camera to preview the URL before clicking to go to the website.
- Don’t scan a QR code in an unexpected email or text message, especially if it urges immediate action. If you think the message is legitimate, you should use a known and trusted phone number or website.
- Protect your phone and online accounts. Regularly update your phone's operating system and protect your accounts with strong passwords and MFA.
Comments