Cart £0.00
0
0
Subtotal: £0.00

No products in the basket.

No products in the basket.

Stealthy QR Code Phishing Attacks Bypass Security with HTML Tables

QR code phishing attack on a laptop screen.

Cybercriminals are employing a novel technique to bypass security measures in QR code phishing campaigns. By embedding QR codes within HTML tables rather than as image files, attackers are successfully circumventing detection systems in email services. This method exploits a blind spot in how security tools analyze email content, allowing malicious QR codes to reach unsuspecting users.

Key Takeaways

  • Attackers are using HTML tables to construct QR codes directly within email bodies.
  • This technique evades detection by email security gateways that primarily scan for image-based QR codes.
  • The malicious QR codes redirect users to credential-stealing phishing websites.
  • The campaign was observed between December 22 and December 26.

The HTML Table Trick

Recent phishing campaigns, observed from December 22 to December 26, have utilized HTML tables to render QR codes. Instead of attaching an image file, threat actors construct the QR code using a series of tiny table cells, each styled with black or white backgrounds to form the recognizable pattern. This approach tricks email service providers’ detection mechanisms, which are often designed to identify QR codes embedded as images.

Bypassing Security Defenses

Security tools that are programmed to scan for image attachments or inline image data often fail to recognize QR codes generated through HTML table markup. To these systems, the email content appears as standard layout code with color attributes, rather than a potentially malicious graphical element. This allows the "imageless" QR codes to slip past automated checks.

The Phishing Payload

Once scanned, these HTML-generated QR codes redirect users to credential-stealing phishing sites. Analysis of these campaigns revealed that the malicious QR codes often point to subdomains of lidoustoo[.]click. To appear more convincing, the URLs sometimes incorporate the recipient’s own domain name in the path, making the link seem less suspicious at first glance.

Sophistication and User Awareness

The use of HTML tables highlights the increasing sophistication of threat actors in developing methods to bypass security defenses. Experts emphasize that purely technical security controls are insufficient against threats that incorporate socio-technical elements. This campaign serves as a reminder for users to exercise caution when scanning QR codes from unsolicited emails, treating them with the same skepticism as unknown links.

Sources

Scroll to Top