Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Using Malicious QR Codes for Phishing via HTML Table

Recent developments in phishing tactics demonstrate an evolution in the use of QR codes, known as "quishing," where threat actors are transitioning from image-based payloads to "imageless" QR codes embedded directly in email HTML. This approach is…

Recent developments in phishing tactics demonstrate an evolution in the use of QR codes, known as "quishing," where threat actors are transitioning from image-based payloads to "imageless" QR codes embedded directly in email HTML. This approach is designed to bypass security tools that typically focus on decoding QR images.

QR code misuse remains prevalent due to its seamless user experience, where a quick scan can initiate a browser session on a mobile device, often outside the security boundaries of corporate endpoints and email inspection processes.

Traditional security measures often fail to detect QR phishing attempts because these controls are usually configured to inspect text, links, and attachments. QR codes, when presented as images, appear meaningless until decoded. In response, attackers are now avoiding image embedding entirely.

Imageless QR Codes in Phishing Attacks

Instead of using image files such as PNG or JPEG, attackers construct QR codes using HTML tables consisting of numerous small cells, each assigned a black or white background color. This method results in QR codes that may appear distorted but effectively evade conventional image analysis pipelines.

This approach is designed to bypass security tools that typically focus on decoding QR images.
Anna Fields · Thehackingpost

Security measures that rely on image detection must adapt, as this new technique lacks a discrete image object for analysis. Even advanced defenses that decode QR codes from images need to first identify the presence of a QR code, a process complicated by the use of HTML layout elements to represent pixels.

Researchers have reported that recent phishing attempts utilized minimalistic emails featuring social-engineering text and a QR code. Scanning these QR codes led victims to credential-harvesting sites. The URLs were also tailored to recipients, complicating reputation-based detection efforts.

To enhance QR code security, it is recommended to tighten controls that extend beyond embedded graphics. This includes flagging unusual HTML constructs, correlating suspicious QR-related language with sender reputation, and enforcing strong authentication for logins initiated from mobile browsers.

Advertisement

There is an emphasis on pre-delivery blocking and layered inspection methods, such as extracting encoded URLs and sandboxing them, rather than relying solely on post-delivery remediation. Users are advised to verify destinations and avoid entering credentials after navigating via QR codes, as threats often manifest only after the scan resolves to a malicious site.

The evolution of phishing tactics highlights the need for security measures that anticipate unconventional representations of risky content. As demonstrated by imageless QR codes, it is crucial to adapt defenses to detect security threats that may not be immediately apparent.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories