Skip to main content

Phishing on the Edge of the Web and Mobile Using QR Codes

0
Medium
Published: 02/14/2026 (02/14/2026, 03:41:01 UTC)
Source: AlienVault OTX General

Description

This article explores the misuse of QR codes in phishing attacks, focusing on three key areas: QR codes with URL shorteners concealing malicious destinations, in-app deep links used to steal credentials and control victims' apps, and QR codes bypassing app store security via direct malicious app downloads. The research reveals an average of 11,000 daily detections of malicious QR codes, with financial services being the most targeted industry. Attackers are leveraging QR code shorteners, in-app deep links, and direct downloads to evade security controls and exploit users' trust in QR codes. The article highlights specific attack scenarios, including account takeovers through messaging apps and distribution of suspicious gambling apps.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 12:44:48 UTC

Technical Analysis

The threat consists of phishing attacks leveraging QR codes as an attack vector. Attackers exploit URL shorteners embedded in QR codes to conceal malicious URLs, use in-app deep links to hijack app sessions and steal credentials, and deliver malicious apps directly to devices, circumventing app store protections. The research identifies a high volume of daily malicious QR code detections, predominantly targeting financial services. The attacks enable account takeovers and distribution of malware, including suspicious gambling applications. This vector exploits user trust and the convenience of QR codes to bypass traditional security controls.

Potential Impact

Users scanning malicious QR codes risk being redirected to harmful websites, having their credentials stolen via in-app deep links, or unknowingly downloading malicious applications. This can lead to account takeovers, unauthorized access to sensitive information, and installation of malware on devices. Financial services customers are particularly at risk, potentially resulting in financial fraud and loss. The threat undermines trust in QR codes and can facilitate broader compromise of user devices and accounts.

Defensive Guidance

No specific patch or fix is available as this is a social engineering and delivery vector rather than a software vulnerability. Users and organizations should educate about the risks of scanning untrusted QR codes, verify URLs before interacting, and use security solutions capable of detecting malicious URLs and apps. Mobile device security settings should restrict app installations from unknown sources. Monitoring for suspicious app behavior and credential anomalies can help detect exploitation. Since this is not a software vulnerability, no official patch exists; mitigation relies on user awareness and security controls.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://unit42.paloaltonetworks.com/qr-codes-as-attack-vector/"]
Pulse Id
698feecd9634c758b58f2ace

Indicators of Compromise

Domain

ValueDescriptionCopy
domain2fbing.com
domainawawc.icu
domainbostonsportsthenandnow.com
domaingricanjolt.com
domaingui-grafit.online
domaingui-snitch.online
domainkccomputech.in
domainkropyva-group.online
domainkzeva2010.sbs
domainmalicious-website.com
domainqrcc.io
domainradenspinrtp.cloud
domainsignal-qr.org
domainsnitch-dev.space
domainsolulu.vip
domainve1edm.cc
domainve2edm.cc
domainweppf.icu
domainwswwc.icu
domainxx.com
domain90999.fdjk34sddsf90999.cc
domainazojwdsj.xinchaoshan.com
domaincdnimg.jeayacrai.in.net
domaincsdh.wangzhan.mobi
domainfable.tele-tale.cn
domaingld45a.cqxqlsz.com
domaingui.dev-snitch.cloud
domaingui.dev-snitch.online
domaingui.dev-snitch.site
domaingui.dev-snitch.xyz
domaingui.snitch-dev.online
domaingui.snitch-dev.site
domaingui.snitch-dev.xyz
domainlink.members-ms.jp
domainresourcepro.tycheint.com
domainsignal.skyriver.ch
domainsnitch.open-group.site
domaint.k12.com.cn
domainwww.malicious-url.com
domainwww.phishing-meeting-link-url.com
domainwww.sgnl-web.org-status.nl
domainxlq.wpybta.icu

Threat ID: 6992f627bda29fb02f678619

Added to database: 02/16/2026, 10:49:11 UTC

Last enriched: 07/31/2026, 12:44:48 UTC

Last updated: 09/08/2026, 10:44:32 UTC

Views: 452

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses