// THREAT DETECTION AND DATA PRIVACY TERM

QR Code Attack

A QR code attack is a cyberattack where a hacker tricks you into scanning a malicious QR code with your smartphone. Scanning the code can lead you to a fraudulent website that steals your information or automatically downloads malware onto your device.

QR Code Attack — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

A QR code attack, also known as quishing, is a mobile-focused cyberattack vector where a threat actor uses a malicious QR (Quick Response) code to deliver a payload, typically by redirecting a user's device to a phishing website for credential harvesting, initiating a malware download, or connecting to a compromised network.

BACKGROUND

Computer security is a subdiscipline within the field of information security. It focuses on protecting computer software, systems, and networks from threats that can lead to unauthorized information disclosure, theft, or damage to hardware, software, or data, as well as to the disruption or misdirection of the services they provide.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • Quishing
  • QR Phishing
  • Malicious QR Code
  • QR Code Scam
  • QR Poisoning
  • Attagging

USAGE NOTE

These attacks often exploit user trust by placing malicious codes over legitimate ones on physical materials like posters or menus.

DEVELOPERS

Organizations developing technology related to QR Code Attack.

  • Abnormal Security

    Develops an AI-powered email security platform that detects and blocks advanced social engineering attacks, including 'quishing' campaigns that use malicious QR codes to bypass traditional security filters.

  • Proofpoint

    Provides comprehensive email security and threat protection solutions that identify and quarantine messages containing malicious QR codes, protecting users from phishing links and malware downloads.

  • Zscaler

    Offers a cloud-native Zero Trust security platform that inspects all user traffic, including links opened from QR codes, to block access to malicious websites and prevent phishing or malware-based attacks.

  • Lookout

    Specializes in mobile endpoint security, offering a Mobile Threat Defense (MTD) platform that protects devices from phishing attempts initiated via QR codes by detecting and blocking malicious URLs and content.

  • Check Point Software Technologies

    Develops the Harmony Mobile solution, a mobile threat defense technology specifically designed to protect corporate data on mobile devices from cyber threats, including phishing attacks initiated by scanning malicious QR codes.

  • Palo Alto Networks

    Offers a suite of security products, including Prisma Access and Cortex XDR, that provide multi-layered defense against threats from QR codes by inspecting web traffic and monitoring endpoint behavior for malicious activity.

  • IRONSCALES

    Provides an AI-driven email security platform that specializes in detecting sophisticated phishing attacks. The technology is trained to recognize and flag QR code-based phishing attempts that target employees.

  • Microsoft

    Incorporates QR code threat protection into its Microsoft Defender for Office 365 service, which uses image detection and URL scanning to identify and block malicious QR codes within emails.

RELATED TERMS IN THREATS & ATTACKS