Quishing: the new threat of malicious QR codes

Do you think you’re safe by scanning a simple QR code? Think again. A new sneaky phishing technique, dubbed “quishing,” exploits these codes to deceive even the most advanced cybersecurity systems. How do these cybercriminals manage to outsmart our digital defenses? Discover the ins and outs of this insidious threat.

The 3 must-know facts

  • Cybercriminals use QR codes to bypass traditional email security systems.
  • The “quishing” technique involves drawing QR codes in HTML, making them harder to detect.
  • Artificial intelligence facilitates the creation of convincing fake websites, increasing the risk of data theft.

The quishing technique

In response to the constant evolution of cybersecurity solutions, cybercriminals innovate with “quishing.” Instead of sending classic malicious links, they send QR codes to scan, thus bypassing detection systems. This method relies on the illusion of security provided by these visual codes, often perceived as harmless.

QR codes in HTML: an effective trick

Jan Kopriva, a cybersecurity researcher, recently highlighted a quishing campaign exploiting a clever technique: drawing QR codes using HTML code. This approach allows cybercriminals to conceal their malicious intentions in a format that many security systems struggle to analyze, as they primarily focus on images.

📊 Comment certains vendeurs dépassent 1 000 €/mois sur Vinted ?

Un vide-dressing occasionnel rapporte rarement plus de 200 € par mois. Mais l'écart avec les vendeurs les plus performants est plus large qu'on ne le pense : 300 à 900 €/mois pour une activité régulière (2 à 5h/semaine), et 1 000 à 2 500 €+/mois pour les profils qui traitent Vinted comme un vrai canal de vente structuré. La différence ne tient ni à la chance ni à la taille du dressing de départ : elle tient presque entièrement à la méthode (algorithme, pricing, réactivité) appliquée avec régularité.

Avec 📘 Le Guide Vinted, transformez ce canal en revenu complémentaire structuré, voire en une vraie activité e-commerce.
Une méthode complète pour décoder l'algorithme, optimiser vos annonces comme une landing page, automatiser votre relance commerciale et sécuriser votre activité sur le plan fiscal.

🧠 Les 5 facteurs qui pilotent la visibilité de vos annonces (logique proche du SEO)
📈 Une méthode réplicable pour passer d'une activité occasionnelle à un revenu récurrent
⚖️ Statut, fiscalité, professionnalisation : rester en règle en montant en volume
🚫 Le chapitre que personne n'aborde ailleurs : comprendre et prévenir les blocages de compte

→ Découvrir la méthode complète (19,99 € au lieu de 29,99 €)

✨ Un guide accessible qui détaille pas à pas le fonctionnement de Vinted, les méthodes de vente qui fonctionnent... et vous verrez que certaines astuces simples et gratuites sur les annonces font toute la différence.

Although this method is not entirely new, its use in real attacks demonstrates that the assumptions on which some digital defenses rely are not always reliable. This underscores the importance of constant technological monitoring to anticipate such developments.

The role of artificial intelligence

Artificial intelligence plays a crucial role in the evolution of phishing techniques. It allows scammers to create fraudulent websites that perfectly mimic the appearance and functionality of legitimate sites. These fake sites often feature apparent security elements, such as the HTTPS protocol or legal notices, making it even more difficult for victims.

As explained by a Kaspersky developer, AI-based tools make the creation of these sites very fast and inexpensive, significantly increasing the risks for unsuspecting users.

Context and history of phishing

Phishing is an online scam method that has existed since the early days of the Internet. It generally involves tricking users into disclosing sensitive information, such as login credentials or banking details. Over the years, techniques have evolved from “scam” type emails to more sophisticated methods like spear phishing, which targets specific individuals.

With the rise of smartphones and mobile Internet, QR codes have become practical tools for quickly sharing information. However, their popularity has also made them a prime target for cybercriminals. Quishing is just the latest evolution of this persistent threat, highlighting the need for increased vigilance and ongoing cybersecurity education.

Source:

[New] 4 ebooks on digital marketing available for free download

Did you enjoy this article? Receive our next articles by email.

Sign up for our newsletter, and you will receive an email every Thursday with the latest articles published by experts.

Other articles on the same topic:

Leave a Reply

Your email address will not be published. Required fields are marked *