Detection Method: QR code analysis

QR code analysis scans and decodes QR codes in emails, attachments, or links to uncover potential security threats that could affect you. This method extracts data from QR codes, checking for malicious URLs, phishing attempts, or harmful contact information.
QR code analysis can help you detect:
  • Phishing links camouflaged as legitimate QR codes in attachments or images
  • Malicious URLs redirecting you to credential harvesting sites
  • QR codes that prompt automatic downloads of malware
  • QR codes containing social engineering information
For example, attackers often use QR codes in phishing campaigns to bypass URL filters. Since you can’t preview the destination before scanning, this method is highly effective at deceiving unsuspecting recipients .
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Compensation review with QR code in attached EML
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/compensation-review-with-qr-code-in-attached-eml-98a2f03c
ClickFunnels link infrastructure abuse
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9
Attachment: Compensation review lure with QR code
14d ago
Oct 29th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c
Constant Contact link infrastructure abuse
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/constant-contact-link-infrastructure-abuse-8c5e8e4c
Brand Impersonation: Google (QR Code)
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-google-qr-code-7ffd184c
Brand impersonation: DocuSign with embedded QR code
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-with-embedded-qr-code-f5cde463
QR Code with suspicious indicators
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f
QR code to auto-download of a suspicious file type (unsolicited)
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/qr-code-to-auto-download-of-a-suspicious-file-type-unsolicited-eed87ea2
Brand impersonation: DocuSign (QR code)
28d ago
Oct 15th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-qr-code-0b16c28a
Attachment: PDF with recipient email in link
1mo ago
Oct 10th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-recipient-email-in-link-0399d08f
Brand impersonation: Adobe (QR code)
1mo ago
Oct 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-adobe-qr-code-2fc36c6d
Brand impersonation: Microsoft (QR code)
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-qr-code-ed0f772a
Attachment: QR code with credential phishing indicators
2mo ago
Sep 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
Unicode QR code
2mo ago
Aug 25th, 2025
Sublime Security
/feeds/core/detection-rules/unicode-qr-code-1a0bdd25
Attachment: SVG files with evasion elements
3mo ago
Aug 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-svg-files-with-evasion-elements-5d2dbb60
Attachment: QR code link with base64-encoded recipient address
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-link-with-base64-encoded-recipient-address-927a0c1a
Attachment: QR code with userinfo portion
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-userinfo-portion-9d62cc5c
Attachment: Fake voicemail via PDF
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-fake-voicemail-via-pdf-d3587209
Link: QR Code with suspicious language (untrusted sender)
3mo ago
Jul 30th, 2025
Sublime Security
/feeds/core/detection-rules/link-qr-code-with-suspicious-language-untrusted-sender-25a84d1c
Link: QR code with phishing disposition in img or pdf
3mo ago
Jul 30th, 2025
Sublime Security
/feeds/core/detection-rules/link-qr-code-with-phishing-disposition-in-img-or-pdf-8e8949f6