Phishing techniques using QR codes, or quishing, is getting more advanced, as security researchers at Barracuda Networks revealed two new methods involving split malicious QR codes and embedded malware in legitimate QR codes.
Phishing-as-a-service operators Gabagool and Tycoon 2FA have recently started using new techniques in quishing to avoid detection.
One of the techniques involves the splitting of a QR code into two separate images, and then embedding them in an email.
When these emails are scanned by traditional security tools, the images look harmless individually rather than a complete QR code. The recipient however sees a complete QR code that can be scanned, which then directs them to a phishing page designed to steal some of their login credentials.
The HTML, however, registers as two different images in order to evade detection.
The other technique includes nested QR codes, where threat actors embed a malicious QR code within or around a legitimate QR code.
This technique can make it harder for scanners to detect the threat, as the results from two combined QR codes are ambiguous.
Recommended reading
- Ransomware Groups are Adjusting Their Strategies
- Phishing Trends: Quishing and AI On the Rise
- Comment | The Rise in QR Code Attacks
Gabagool is using the split QR method in a fraudulent Microsoft password recent scheme, where as Tycoon 2FA’s nested QR technique is being used on a range of malicious webpage redirects.
The new techniques shows the troubling evolution of QR code attacks as their expanding use cases.
Barracuda Networks recommends that organisations consider multilayered email protections that integrate multimodal AI on top of traditional security measures to combat the rising and increasingly sophisticated threat.
Multimodal AI has deep image processing capabilities, which may make it more difficult for split and nested QR campaigns to evade detection.





