Phishing on the Edge of the Web and Mobile Using QR Codes
This article explores the misuse of QR codes in phishing attacks, focusing on three key areas: QR codes with URL shorteners concealing malicious destinations, in-app deep links used to steal credentials and control victims' apps, and QR codes bypassing app store security via direct malicious app downloads. The research reveals an average of 11,000 daily detections of malicious QR codes, with financial services being the most targeted industry. Attackers are leveraging QR code shorteners, in-app deep links, and direct downloads to evade security controls and exploit users' trust in QR codes. The article highlights specific attack scenarios, including account takeovers through messaging apps and distribution of suspicious gambling apps.
AI Analysis
Technical Summary
The threat consists of phishing attacks leveraging QR codes as an attack vector. Attackers exploit URL shorteners embedded in QR codes to conceal malicious URLs, use in-app deep links to hijack app sessions and steal credentials, and deliver malicious apps directly to devices, circumventing app store protections. The research identifies a high volume of daily malicious QR code detections, predominantly targeting financial services. The attacks enable account takeovers and distribution of malware, including suspicious gambling applications. This vector exploits user trust and the convenience of QR codes to bypass traditional security controls.
Potential Impact
Users scanning malicious QR codes risk being redirected to harmful websites, having their credentials stolen via in-app deep links, or unknowingly downloading malicious applications. This can lead to account takeovers, unauthorized access to sensitive information, and installation of malware on devices. Financial services customers are particularly at risk, potentially resulting in financial fraud and loss. The threat undermines trust in QR codes and can facilitate broader compromise of user devices and accounts.
Mitigation Recommendations
No specific patch or fix is available as this is a social engineering and delivery vector rather than a software vulnerability. Users and organizations should educate about the risks of scanning untrusted QR codes, verify URLs before interacting, and use security solutions capable of detecting malicious URLs and apps. Mobile device security settings should restrict app installations from unknown sources. Monitoring for suspicious app behavior and credential anomalies can help detect exploitation. Since this is not a software vulnerability, no official patch exists; mitigation relies on user awareness and security controls.
Indicators of Compromise
- domain: 2fbing.com
- domain: awawc.icu
- domain: bostonsportsthenandnow.com
- domain: gricanjolt.com
- domain: gui-grafit.online
- domain: gui-snitch.online
- domain: kccomputech.in
- domain: kropyva-group.online
- domain: kzeva2010.sbs
- domain: malicious-website.com
- domain: qrcc.io
- domain: radenspinrtp.cloud
- domain: signal-qr.org
- domain: snitch-dev.space
- domain: solulu.vip
- domain: ve1edm.cc
- domain: ve2edm.cc
- domain: weppf.icu
- domain: wswwc.icu
- domain: xx.com
- domain: 90999.fdjk34sddsf90999.cc
- domain: azojwdsj.xinchaoshan.com
- domain: cdnimg.jeayacrai.in.net
- domain: csdh.wangzhan.mobi
- domain: fable.tele-tale.cn
- domain: gld45a.cqxqlsz.com
- domain: gui.dev-snitch.cloud
- domain: gui.dev-snitch.online
- domain: gui.dev-snitch.site
- domain: gui.dev-snitch.xyz
- domain: gui.snitch-dev.online
- domain: gui.snitch-dev.site
- domain: gui.snitch-dev.xyz
- domain: link.members-ms.jp
- domain: resourcepro.tycheint.com
- domain: signal.skyriver.ch
- domain: snitch.open-group.site
- domain: t.k12.com.cn
- domain: www.malicious-url.com
- domain: www.phishing-meeting-link-url.com
- domain: www.sgnl-web.org-status.nl
- domain: xlq.wpybta.icu
Phishing on the Edge of the Web and Mobile Using QR Codes
Description
This article explores the misuse of QR codes in phishing attacks, focusing on three key areas: QR codes with URL shorteners concealing malicious destinations, in-app deep links used to steal credentials and control victims' apps, and QR codes bypassing app store security via direct malicious app downloads. The research reveals an average of 11,000 daily detections of malicious QR codes, with financial services being the most targeted industry. Attackers are leveraging QR code shorteners, in-app deep links, and direct downloads to evade security controls and exploit users' trust in QR codes. The article highlights specific attack scenarios, including account takeovers through messaging apps and distribution of suspicious gambling apps.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat consists of phishing attacks leveraging QR codes as an attack vector. Attackers exploit URL shorteners embedded in QR codes to conceal malicious URLs, use in-app deep links to hijack app sessions and steal credentials, and deliver malicious apps directly to devices, circumventing app store protections. The research identifies a high volume of daily malicious QR code detections, predominantly targeting financial services. The attacks enable account takeovers and distribution of malware, including suspicious gambling applications. This vector exploits user trust and the convenience of QR codes to bypass traditional security controls.
Potential Impact
Users scanning malicious QR codes risk being redirected to harmful websites, having their credentials stolen via in-app deep links, or unknowingly downloading malicious applications. This can lead to account takeovers, unauthorized access to sensitive information, and installation of malware on devices. Financial services customers are particularly at risk, potentially resulting in financial fraud and loss. The threat undermines trust in QR codes and can facilitate broader compromise of user devices and accounts.
Defensive Guidance
No specific patch or fix is available as this is a social engineering and delivery vector rather than a software vulnerability. Users and organizations should educate about the risks of scanning untrusted QR codes, verify URLs before interacting, and use security solutions capable of detecting malicious URLs and apps. Mobile device security settings should restrict app installations from unknown sources. Monitoring for suspicious app behavior and credential anomalies can help detect exploitation. Since this is not a software vulnerability, no official patch exists; mitigation relies on user awareness and security controls.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://unit42.paloaltonetworks.com/qr-codes-as-attack-vector/"]
- Pulse Id
- 698feecd9634c758b58f2ace
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domain2fbing.com | — | |
domainawawc.icu | — | |
domainbostonsportsthenandnow.com | — | |
domaingricanjolt.com | — | |
domaingui-grafit.online | — | |
domaingui-snitch.online | — | |
domainkccomputech.in | — | |
domainkropyva-group.online | — | |
domainkzeva2010.sbs | — | |
domainmalicious-website.com | — | |
domainqrcc.io | — | |
domainradenspinrtp.cloud | — | |
domainsignal-qr.org | — | |
domainsnitch-dev.space | — | |
domainsolulu.vip | — | |
domainve1edm.cc | — | |
domainve2edm.cc | — | |
domainweppf.icu | — | |
domainwswwc.icu | — | |
domainxx.com | — | |
domain90999.fdjk34sddsf90999.cc | — | |
domainazojwdsj.xinchaoshan.com | — | |
domaincdnimg.jeayacrai.in.net | — | |
domaincsdh.wangzhan.mobi | — | |
domainfable.tele-tale.cn | — | |
domaingld45a.cqxqlsz.com | — | |
domaingui.dev-snitch.cloud | — | |
domaingui.dev-snitch.online | — | |
domaingui.dev-snitch.site | — | |
domaingui.dev-snitch.xyz | — | |
domaingui.snitch-dev.online | — | |
domaingui.snitch-dev.site | — | |
domaingui.snitch-dev.xyz | — | |
domainlink.members-ms.jp | — | |
domainresourcepro.tycheint.com | — | |
domainsignal.skyriver.ch | — | |
domainsnitch.open-group.site | — | |
domaint.k12.com.cn | — | |
domainwww.malicious-url.com | — | |
domainwww.phishing-meeting-link-url.com | — | |
domainwww.sgnl-web.org-status.nl | — | |
domainxlq.wpybta.icu | — |
Threat ID: 6992f627bda29fb02f678619
Added to database: 02/16/2026, 10:49:11 UTC
Last enriched: 07/31/2026, 12:44:48 UTC
Last updated: 09/08/2026, 10:44:32 UTC
Views: 452
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.