QR Codes Used to Spread Phishing Attacks and Malicious Apps Across Mobile Devices
QR codes are increasingly being used for various digital interactions, such as accessing links, processing payments, and signing in. However, this convenience also opens avenues for attackers to redirect users to potentially harmful web pages or…
QR codes are increasingly being used for various digital interactions, such as accessing links, processing payments, and signing in. However, this convenience also opens avenues for attackers to redirect users to potentially harmful web pages or applications swiftly.
Recent campaigns have shown that QR codes themselves are not inherently malicious but serve as a delivery mechanism for threats. They can mask extensive redirect chains, trigger in-app deep links, or facilitate direct downloads that bypass app-store security checks. This method, known as 'quishing,' has been observed in both emails and physical posters.
Palo Alto Networks researchers have reported a rise in malicious activity involving QR codes. Their surveillance indicates approximately 75,000 QR codes are scanned daily, with about 15% leading to malicious links, resulting in over 11,000 detections each day.
Given that most QR scans occur on personal mobile devices with less stringent security controls than corporate desktops, a single scan can lead users outside the secure corporate network to potentially harmful pages. Additionally, attackers may employ QR shorteners to alter destinations or deactivate links after a short period.
QR codes are increasingly being used for various digital interactions, such as accessing links, processing payments, and signing in.
Deep links, which open specific screens within applications, have been exploited in over 35,000 QR codes associated with Telegram deep links. Of these, 'tglogin' links represent 97% of cases, with about 20% of host pages appearing malicious. Other campaigns have targeted new sessions in apps like Signal, WhatsApp, or Line, with a focus on Ukrainian Signal users.
Palo Alto Networks discovered in-app deep links in approximately 3% of QR codes. These links can be challenging to detect through standard web analysis and often require mobile sandbox environments for thorough investigation.
Treat QR codes as untrusted inputs and scan them prior to user interaction. Expand monitoring to include QR images in web content and documents. Block known QR shortener abuse and restrict direct APK installations. Strengthen email and web filtering to identify and prevent QR-based phishing and malware campaigns. Conduct continuous user awareness training to minimize susceptibility to these threats.
User Recommendations: Always verify the source of QR codes, preview links before opening them, and avoid urgent payment requests. Refrain from approving app logins or device links from unknown QR codes, ensure your operating system is up to date, and disable settings for installing unknown apps.
Based on reporting by Cyber Security News.
