
Threat actors have a habit of recycling old techniques with new delivery methods, and QR code phishing, also known as “Quishing”, is just another example. Just a week after Gurucul published a thorough analysis into Adversary-in-the-Middle (AITM) attacks, a similar threat vector has emerged as malicious QR codes embedded in phishing emails. These attacks are gaining momentum, exploiting both end-user trust and the gaps in traditional security tools. Much like AITM, QR-based phishing sidesteps email gateway protections and leverages trusted access to compromised identities.
At a recent customer site, Gurucul’s analytics detected a QR code phishing attempt that completely bypassed legacy email gateways and network/endpoint detection tools. The attack used an embedded QR code in an email attachment to redirect users to a spoofed login page. The scan redirected victims to a credential-harvesting site that imitated a legitimate identity provider. What made this case significant was that traditional tools failed to generate an alert. Gurucul’s behavioral analytics and entity risk scoring models, however, flagged the incident based on a chain of correlated anomalies.
Gurucul detected QR code phishing campaigns by connecting data across multiple silos:
Beyond siloed analysis, Gurucul stitches together weak signals to reveal the full attack chain:
As phishing techniques evolve, so must our approach to detection. QR code scams are increasing, but they’re only a small part of a much bigger problem. Generative AI is now being used by threat actors to launch highly targeted social engineering and phishing attacks, especially against less tech-savvy industries. These AI-powered campaigns personalize attacks, increasing their speed and scale beyond the capabilities of traditional defenses.
As identity remains the new perimeter, and deception the weapon of choice, Gurucul’s behavioral analytics and advanced threat correlation continue to offer a critical edge against modern attack techniques.