The Trail: From AITM to the Resurgence of QR Code Phishing

The Trail-From AITM to the Resurgence of QR Code Phishing-Blog Inline Image
Threat actors have a habit of recycling old techniques with new delivery methods, and QR code phishing, also known as “Quishing”, is just another example. Just a week after Gurucul published a thorough analysis into Adversary-in-the-Middle (AITM) attacks, a similar threat vector has emerged as malicious QR codes embedded in phishing emails. These attacks are gaining momentum, exploiting both end-user trust and the gaps in traditional security tools. Much like AITM, QR-based phishing sidesteps email gateway protections and leverages trusted access to compromised identities.

Real-World Detection: A Quishing Attack Uncovered

At a recent customer site, Gurucul’s analytics detected a QR code phishing attempt that completely bypassed legacy email gateways and network/endpoint detection tools. The attack used an embedded QR code in an email attachment to redirect users to a spoofed login page. The scan redirected victims to a credential-harvesting site that imitated a legitimate identity provider. What made this case significant was that traditional tools failed to generate an alert. Gurucul’s behavioral analytics and entity risk scoring models, however, flagged the incident based on a chain of correlated anomalies.

QR Code Phishing (Quishing)

How Gurucul Detects QR Code Phishing (Quishing) Attacks

Gurucul detected QR code phishing campaigns by connecting data across multiple silos:

Cross-Platform Behavior Correlation

  • Email Gateway Metadata: Identifies anomalies in attachments or email sender domain.
  • Web Proxy Logs: Flags QR-originated traffic leading to newly registered or untrusted domains.
  • Identity Provider Logs: Detect abnormal authentication attempts post-scan.
  • Cloud Audit Logs: Captures suspicious changes in identity settings or privileges.
  • Geo-Intel and Credential Abuse Patterns: Combines geo-anomalies, password stuffing patterns, and threat intel data to establish high-confidence alerts.

Suspicious Activity Chaining

Beyond siloed analysis, Gurucul stitches together weak signals to reveal the full attack chain:

  • A benign-looking email from unusual sender domain
  • User scan activity from a personal device
  • Unusual redirect through proxy
  • Token theft or credential submission
  • Suspicious login attempt from a new location/device, unusual ISP
  • Gurucul’s Chain Model helps in detection of post-compromise behaviors, such as Lateral Movements, privilege escalation, internal phishing campaigns, etc.

Looking Ahead

As phishing techniques evolve, so must our approach to detection. QR code scams are increasing, but they’re only a small part of a much bigger problem. Generative AI is now being used by threat actors to launch highly targeted social engineering and phishing attacks, especially against less tech-savvy industries. These AI-powered campaigns personalize attacks, increasing their speed and scale beyond the capabilities of traditional defenses.

As identity remains the new perimeter, and deception the weapon of choice, Gurucul’s behavioral analytics and advanced threat correlation continue to offer a critical edge against modern attack techniques.

Advanced cyber security analytics platform visualizing real-time threat intelligence, network vulnerabilities, and data breach prevention metrics on an interactive dashboard for proactive risk management and incident response