Detection Method: QR code analysis

QR code analysis scans and decodes QR codes in emails, attachments, or links to uncover potential security threats that could affect you. This method extracts data from QR codes, checking for malicious URLs, phishing attempts, or harmful contact information.
QR code analysis can help you detect:
  • Phishing links camouflaged as legitimate QR codes in attachments or images
  • Malicious URLs redirecting you to credential harvesting sites
  • QR codes that prompt automatic downloads of malware
  • QR codes containing social engineering information
For example, attackers often use QR codes in phishing campaigns to bypass URL filters. Since you can’t preview the destination before scanning, this method is highly effective at deceiving unsuspecting recipients .
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF with recipient email in link
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-recipient-email-in-link-0399d08f
Attachment: QR code with recipient targeting and special characters
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-recipient-targeting-and-special-characters-fc9e1c09
Service abuse: Monday.com infrastructure with phishing intent
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-mondaycom-infrastructure-with-phishing-intent-a346e3b1
Brand impersonation: Adobe (QR code)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-adobe-qr-code-2fc36c6d
Brand impersonation: Microsoft (QR code)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-qr-code-ed0f772a
Attachment: QR code link with base64-encoded recipient address
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-link-with-base64-encoded-recipient-address-927a0c1a
Attachment: QR code with userinfo portion
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-userinfo-portion-9d62cc5c
Attachment: HTML smuggling - QR Code with suspicious links
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d
QR Code with suspicious indicators
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f
Attachment: QR code with credential phishing indicators
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
ClickFunnels link infrastructure abuse
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9
Attachment: Compensation review lure with QR code
1mo ago
Dec 10th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c
Link: QR code in EML attachment with credential phishing indicators
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/link-qr-code-in-eml-attachment-with-credential-phishing-indicators-9908ed3a
Compensation review with QR code in attached EML
1mo ago
Nov 26th, 2025
Sublime Security
/feeds/core/detection-rules/compensation-review-with-qr-code-in-attached-eml-98a2f03c
Attachment: Credit card application with WhatsApp contact
2mo ago
Nov 20th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-credit-card-application-with-whatsapp-contact-95b08315
QR code to auto-download of a suspicious file type (unsolicited)
3mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/qr-code-to-auto-download-of-a-suspicious-file-type-unsolicited-eed87ea2
Constant Contact link infrastructure abuse
3mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/constant-contact-link-infrastructure-abuse-8c5e8e4c
Brand impersonation: DocuSign with embedded QR code
3mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-with-embedded-qr-code-f5cde463
Brand Impersonation: Google (QR Code)
3mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-google-qr-code-7ffd184c
Brand impersonation: DocuSign (QR code)
3mo ago
Oct 15th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-qr-code-0b16c28a