started · updated
ESET warns of rising quishing attacks using QR codes
Cybersecurity firm ESET has issued a warning regarding the rise of ‘quishing’, a form of phishing that utilizes QR codes to deceive users. According to the firm, approximately 11% of phishing emails now employ QR codes to facilitate attacks.
Threat actors use QR codes to hide malicious URLs, allowing them to bypass traditional corporate security filters that inspect text-based links. Because the destination is encoded visually rather than as legible text, it is difficult for users to verify the URL before interacting. This technique often shifts the interaction from a monitored corporate computer to a personal mobile device, which typically has fewer security controls.
Mario Micucci, an IT security researcher at ESET Latin America, noted that the ubiquity of QR codes in daily life—such as in menus and parking meters—creates a false sense of security. This familiarity can lead to complacency, making users more susceptible to fraudulent links embedded in QR codes or files like PDFs and JPEGs.