QR codes are being hijacked to bypass MFA protections benedict.collins@futurenet.com (Benedict Collins) | usagoldmines.com

By now, most of us have become accustomed to seeing QR codes everywhere, from cafes and pubs, to businesses and public services. But how often do you check the URL it is directing you to?

This is just one of the weaknesses of QR codes – the implicit trust that the code will take you where you want to go.

New Sophos research has explored how an attack plays out after one of its own employees was targeted in a ‘quishing’ attack which utilized malicious QR codes hidden in seemingly legitimate internal emails.

Squishing quishing isn’t easy

In June 2024, several Sophos employees received a fairly mundane email from legitimate external email accounts, with subject lines written to appear as though the email was sent from an office printer/scanner with an employee benefits PDF document attached.

The PDF was fairly plain, containing the Sophos logo at the top, followed by a QR code and a message at the bottom stating that the QR code contained a secured link to DocuSign which required the employee’s digital signature, and that the file would expire in 24 hours.

A seemingly legitimate email from an office scanner with a PDF file attached. (Image credit: Sophos)

When scanned, the QR code directed the employee to a Microsoft 365 sign-in box, where the employee duly signed in and completed a multi-factor authentication check. In almost real time an attacker used the credentials and a stolen MFA token to attempt to access an internal application. Luckily, Sophos’ internal network settings prevented access and the account was secured.

So, how could a quishing attack such as this be spotted and stopped? Well, if you pay particular attention to every detail of an incoming email, you may just stand a chance. For one, Sophos points out, the file name contained within the body of the email did not match that of the attached PDF. Moreover, the subject line read “Remittance Arrived” – something that a file received from a legitimate officer scanner would not say.

The subject line also ended with “retirements plan attache=”. Whether this was a mistake on behalf of the attacker or a clever use of the ‘=’ sign to make the header appear cut off is not known.

The false sense of urgency proposed by the 24-hour expiry timeline should have also been a giveaway, as well as the URL displayed when the QR code was scanned. However, as anyone who has scanned a QR code before will know, sometimes the full URL isn’t shown or disappears before it can be fully read and checked for clues such as random letters or a homoglyph domain.

A spoofed Microsoft 365 sign-in page. (Image credit: Sophos)

As for the stolen MFA token, the Microsoft 365 sign in page was actually a spoofed dialogue box controlled by the attacker that was not picked up due to a lack of URL filtering software on the victim’s phone.

Quishing, Sophos points out, is fast becoming a growing threat to organizations with phishing-as-a-service (PhaaS) brokers such as the ONNX Store increasingly offering QR code-based attacks in their offerings.

As QR codes are typically image based attachments that can be placed within PDF documents, they can easily slip through email filters and the typical endpoint security protections employed by many businesses, as all of the URL processing happens on the victim’s mobile device that may not be subject to the same level of protection.

Andrew Brandt, principal threat researcher at Sophos said, “While there was some fear surrounding the rise of QR codes when they first became popular during COVID, the risk for most people was actually quite small. However, now we’re seeing attackers leverage these QR codes for highly targeted phishing attacks—and they’re effective.”

“QR codes are incredibly flexible, and with quishing kits, attackers can essentially create a series of targeted quishing emails en masse, customizing them for employees of different companies. And, unfortunately, if attackers manage to steal both login credentials and MFA authentication tokens for a company employee, in many many cases, they have gained the ability to infiltrated highly privileged assets,” Brandt said.

For recommendations on how best to protect your organization from quishing, and the key signs of a quishing email, take a look at Sophos’ suggestions here.

More from TechRadar Pro

These are the best business VPNsProton unveils new business VPN featuresTake a look at our guide to the best business firewalls
​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Galaxy Z Fold 6 Deal Drops $300 Off Instantly, Up to $1,500 Off With Trade Kellen | usagoldmines.com
The Right Way to Vacuum, According to a Dyson Designer Lindsey Ellefson | usagoldmines.com
How to Customize or Disable the Camera Control Button on an iPhone 16 Pranay Parab | usagoldmines.co...
iPad Mini 7 Has Display Hardware Changes That Likely Fix Jelly Scrolling Juli Clover | usagoldmines....
Judge slams Florida for censoring political ad: “It’s the First Amendment, stupid” Jon Brodkin | usa...
Qualcomm’s canceled mini-PC could spell trouble with consumers down the line allisa.james@futurenet....
Bizarre fish has sensory “legs” it uses for walking and tasting Elizabeth Rayne | usagoldmines.com
Best laptops under $500 in 2024: Best overall, best OLED laptop, and more | usagoldmines.com
3 Quick Android 15 Settings to Change on Your Pixel Device Kellen | usagoldmines.com
iPhone 17 Pro Models Again Rumored to Feature 48MP Telephoto Camera, 12GB of RAM, and More Joe Rossi...
Best Apple Deals of the Week: Magic Keyboards Hit Best-Ever Prices, Plus Apple Watch and Anker Sales...
Casio recovery from ransomware attack uncertain, 'no prospect of recovery yet' | usagoldmines.com
Amazon exec tells employees to work elsewhere if they dislike RTO policy Scharon Harding | usagoldmi...
Desalination system adjusts itself to work with renewable power Jacek Krywko | usagoldmines.com
How to Grow Tulips and Other Spring Flowers Indoors This Winter Amanda Blum | usagoldmines.com
These Three Apps Can Help You Remotely Access Your Computer David Nield | usagoldmines.com
Use This Extension to Find All Your X Followers on Bluesky Joel Cunningham | usagoldmines.com
These Halloween Contacts Can Cause Eye Infections Beth Skwarecki | usagoldmines.com
Lapz App Lets You Watch Formula 1 Races on Apple Vision Pro Juli Clover | usagoldmines.com
All-New 'iPhone 17 Air' Rumored to Feature Single 48MP Rear Camera, 8GB of RAM, and More Joe Rossign...
Intel's 128-core wonder processor is also its most expensive CPU right now, Xeon 6980P costs more th...
Ferrari unveils its F1-inspired F80 hybrid supercar – the most powerful Ferrari to roll out of Maran...
US suspects TSMC helped Huawei skirt export controls, report says Ashley Belanger | usagoldmines.com
Logitech’s MX Master 2S wireless mouse is 50% off today | usagoldmines.com
Apple Seeds Sixth Beta of visionOS 2.1 Juli Clover | usagoldmines.com
Boston Children's Health Physicians told to pay up or face leak by ransomware group | usagoldmines....
Elon Musk changes X terms to steer lawsuits to his favorite Texas court Jon Brodkin | usagoldmines.c...
Best VPNs for torrenting 2024: Speed, privacy, and security matter | usagoldmines.com
YouTube is testing a cheaper ‘Premium Lite’ plan… that still has ads | usagoldmines.com
Best SSDs of 2024: Reviews and buying advice | usagoldmines.com
Here’s How to Enable Android 15’s New Notification Syncing Between Pixel Devices Kellen | usagoldmin...
Whatever Happened to Daylight Saving Time Going Away? Beth Skwarecki | usagoldmines.com
Request These Days Off to Maximize Your PTO in 2025 Emily Long | usagoldmines.com
11 of the Best Movies About Real American Presidents Jason Keil | usagoldmines.com
The 11 Best New Horror Movies to Stream This Halloween Stephen Johnson | usagoldmines.com
The MacRumors Show: iPad Mini 7 Is Here! Hartley Charlton | usagoldmines.com
Best Buy Introduces Massive Discounts on M3 MacBook Pro for Members, Get Up to $700 Off Mitchel Brou...
Pro-Ject's new flagship turntable weighs 80lb and costs $15,000… without a cartridge becky.scarrott@...
iOS 18.1: 5 new features to expect, including Apple Intelligence and iPhone Mirroring axel.metz@futu...
Create a whole new world for yourself with inZOI | usagoldmines.com
I find songs I love on social media all the time, so this new Instagram feature is music to my ears ...
Fed up with Windows 11’s look? New mod lets you revamp the desktop, including the floating taskbar o...
Insurance giant Globe Life says it's being extorted by hackers | usagoldmines.com
OpenAI releases ChatGPT app for Windows Benj Edwards | usagoldmines.com
Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com
This beastly MSI gaming laptop with RTX 4070 is $200 off right now | usagoldmines.com
ChatGPT’s desktop app finally comes to Windows, with features missing | usagoldmines.com
Get this Dyson heater-fan combo for 33% off and enjoy year-round comfort | usagoldmines.com
HP Victus 15 review: A budget gaming laptop with a 144Hz display | usagoldmines.com
AVG Internet Security review: Reliable, budget-friendly antivirus software | usagoldmines.com
Asus’ new power supply has a ‘magnetic OLED’ screen, because why the hell not | usagoldmines.com
Call of Duty anti-cheat bug let hackers ban people with a DM | usagoldmines.com
Know Where You Fall on the Happy-Productive Scale to Get More Done at Work Lindsey Ellefson | usagol...
New iPad Mini Ships With iPadOS 18.0, Apple Intelligence Coming Later Joe Rossignol | usagoldmines.c...
Apple Discontinues Powerbeats Pro, But They Will Return Next Year With Heart Rate Monitoring Joe Ros...
'A revolutionary combination of performance and efficiency': Affordable, super fast SSDs as quick as...
Asus ROG Thor III is a massive 1600W PSU that will handle the Nvidia RTX 5090 with ease - but could ...
Squarespace snapped up in billion-dollar deal | usagoldmines.com
Now on DVD: Windows 11 24H2 (yes, really) has been slimmed down and ready for action by Tiny11 devel...
X’s controversial changes to blocking and AI training sees half a million users leave for rival Blue...
Microsoft says it has lost 'weeks' worth of security logs for some products | usagoldmines.com
Critical Kubernetes Image Builder credential vulnerability allows for virtual machine SSH access | ...
Hulu is stealing the saddest rom-com I've seen with 91% on Rotten Tomatoes from Netflix – here’s whe...
The AI at scale revolution disrupting industries | usagoldmines.com
Emerging AI regulation will shape the future of data collection for business | usagoldmines.com
AWS CEO tells workers to quit if they don't want to come back to the office | usagoldmines.com
That Google Meet invite could be a fake, hiding some dangerous malware | usagoldmines.com
Tesla FSD crashes in fog, sun glare—Feds open new safety investigation Jonathan M. Gitlin | usagoldm...
Asus ROG Thor III is a massive 1600W PSU that will handle the Nvidia RTX 5090 with ease - but could ...
Adobe shows off 3D rotation tool for flat drawings Kyle Orland | usagoldmines.com
Manufacturers release patch for SSD-related Windows 11 24H2 crashes | usagoldmines.com
How to auto-lock your PC when you step away (and why you should) | usagoldmines.com
Wireless 6G sets an incredible speed record, makes 5G feel like dial-up | usagoldmines.com
This cheap Bluetooth turntable looks ideal for vinyl beginners – with one potential problem | usago...
Max drops Dune: Prophecy's official trailer and proves that HBO is still the king of original TV sho...
Google Chrome on Android is about to get a massive upgrade for password managers that’s been a long ...
Sonos confirms some missing details about Arc Ultra – and says its app now has 90% of its missing fe...
This fast, budget-friendly 1TB portable SSD just got even cheaper | usagoldmines.com
iPad Mini 7 Benchmarks Confirm 8GB RAM, 5-Core GPU's Slower Speeds Hartley Charlton | usagoldmines.c...
Where to buy the Fujifilm X100VI: current delivery estimates and the best retailers alex.whitelock@f...
Apple expands Business Connect tools to help firms stay in touch with customers | usagoldmines.com
9 must-know details about Windows 11’s big 2024 update | usagoldmines.com
Arm wants to go direct Chinese market, no more ArmChina middleman | usagoldmines.com
OnePlus shares release date for Android 15 update, announces new AI features jamie.richards@futurene...
Google says it has made big steps in improving memory safety | usagoldmines.com
Joe Rogan says the Garmin Fenix 8's cold water problem "sucks" – but he's got a solution matt.evans@...
Netflix teases Virgin River season 6's wedding of the year and I desperately need an invite grace.mo...
Proton unveils new business VPN features benedict.collins@futurenet.com (Benedict Collins) | usagold...
Finally upgrading from isc-dhcp-server to isc-kea for my homelab Lee Hutchinson | usagoldmines.com
Rocket Report: Bloomberg calls for SLS cancellation; SpaceX hits century mark Eric Berger | usagoldm...
Simple voltage pulse can restore capacity to Li-Si batteries John Timmer | usagoldmines.com
You’re not alone – many users are reporting iPhone 16 battery life issues on iOS 18 | usagoldmines....
Don't panic, Facer users, full Wear OS 5 support is coming – eventually stephen.warwick@futurenet.co...
Nvidia is killing off its Control Panel app - and it wants you to help shape its replacement | usag...
Dbrand has returned with new Darkplates 2.0 - bespoke face plates you can put on your PS5 Slim | us...
Looking at buying an SSD? Hold fire for now – prices are predicted to drop (and on top of that, Blac...
Leaked dummy units of all three Samsung Galaxy S25 phones show off their sizes and dimensions | usa...
Navigating the AI skills shortage: Strategies for global CIOs | usagoldmines.com
ChatGPT app comes to Windows finally! Add a quick AI shortcut to your PC today john-anthony.disotto@...
Business heads are struggling to trust AI, but hope it will be a major source of revenue | usagoldm...

Leave a Reply