Tactic or Technique: QR code

QR codes are those square barcodes you scan with your phone to open a link. You’ve probably used them at restaurants, parking meters, or on event flyers. Attackers take advantage of how common and trusted they’ve become by hiding malicious links inside them. When scanned, a QR code can send you to a phishing site or install malware on your device.
These codes often appear in emails, attachments, or printed materials and are designed to look harmless. Some use redirect chains that pass through a URL shortener or compromised site before landing on the actual payload, making them harder to detect.
Because you can’t see where a QR code leads before scanning, and many scans happen on personal phones without enterprise protections, attackers get a reliable way to steal credentials, install malware, or access corporate systems through unmanaged devices.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF with recipient email in link
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-recipient-email-in-link-0399d08f
Attachment: QR code with recipient targeting and special characters
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-recipient-targeting-and-special-characters-fc9e1c09
QR Code with suspicious indicators
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f
Attachment: HTML smuggling - QR Code with suspicious links
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d
Brand impersonation: Adobe (QR code)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-adobe-qr-code-2fc36c6d
Brand impersonation: Microsoft (QR code)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-qr-code-ed0f772a
Attachment: QR code link with base64-encoded recipient address
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-link-with-base64-encoded-recipient-address-927a0c1a
Attachment: QR code with userinfo portion
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-userinfo-portion-9d62cc5c
Service abuse: Monday.com infrastructure with phishing intent
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-mondaycom-infrastructure-with-phishing-intent-a346e3b1
Attachment: QR code with credential phishing indicators
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
Attachment: Compensation review lure with QR code
1mo ago
Dec 10th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c
Link: QR code in EML attachment with credential phishing indicators
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/link-qr-code-in-eml-attachment-with-credential-phishing-indicators-9908ed3a
Compensation review with QR code in attached EML
1mo ago
Nov 26th, 2025
Sublime Security
/feeds/core/detection-rules/compensation-review-with-qr-code-in-attached-eml-98a2f03c
Brand impersonation: DocuSign with embedded QR code
3mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-with-embedded-qr-code-f5cde463
Brand Impersonation: Google (QR Code)
3mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-google-qr-code-7ffd184c
Brand impersonation: DocuSign (QR code)
3mo ago
Oct 15th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-qr-code-0b16c28a
Attachment: SVG files with evasion elements
5mo ago
Aug 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-svg-files-with-evasion-elements-5d2dbb60
Attachment: Fake voicemail via PDF
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-fake-voicemail-via-pdf-d3587209
Link: QR Code with suspicious language (untrusted sender)
5mo ago
Jul 30th, 2025
Sublime Security
/feeds/core/detection-rules/link-qr-code-with-suspicious-language-untrusted-sender-25a84d1c
Link: QR code with phishing disposition in img or pdf
5mo ago
Jul 30th, 2025
Sublime Security
/feeds/core/detection-rules/link-qr-code-with-phishing-disposition-in-img-or-pdf-8e8949f6