Tactic or Technique: QR code

QR codes are those square barcodes you scan with your phone to open a link. You’ve probably used them at restaurants, parking meters, or on event flyers. Attackers take advantage of how common and trusted they’ve become by hiding malicious links inside them. When scanned, a QR code can send you to a phishing site or install malware on your device.
These codes often appear in emails, attachments, or printed materials and are designed to look harmless. Some use redirect chains that pass through a URL shortener or compromised site before landing on the actual payload, making them harder to detect.
Because you can’t see where a QR code leads before scanning, and many scans happen on personal phones without enterprise protections, attackers get a reliable way to steal credentials, install malware, or access corporate systems through unmanaged devices.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Compensation review with QR code in attached EML
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/compensation-review-with-qr-code-in-attached-eml-98a2f03c
Attachment: Compensation review lure with QR code
14d ago
Oct 29th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c
Brand Impersonation: Google (QR Code)
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-google-qr-code-7ffd184c
Brand impersonation: DocuSign with embedded QR code
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-with-embedded-qr-code-f5cde463
QR Code with suspicious indicators
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f
Brand impersonation: DocuSign (QR code)
28d ago
Oct 15th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-qr-code-0b16c28a
Attachment: PDF with recipient email in link
1mo ago
Oct 10th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-recipient-email-in-link-0399d08f
Brand impersonation: Adobe (QR code)
1mo ago
Oct 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-adobe-qr-code-2fc36c6d
Brand impersonation: Microsoft (QR code)
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-qr-code-ed0f772a
Attachment: QR code with credential phishing indicators
2mo ago
Sep 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
Attachment: SVG files with evasion elements
3mo ago
Aug 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-svg-files-with-evasion-elements-5d2dbb60
Attachment: QR code with userinfo portion
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-userinfo-portion-9d62cc5c
Attachment: Fake voicemail via PDF
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-fake-voicemail-via-pdf-d3587209
Attachment: QR code link with base64-encoded recipient address
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-link-with-base64-encoded-recipient-address-927a0c1a
Link: QR code with phishing disposition in img or pdf
3mo ago
Jul 30th, 2025
Sublime Security
/feeds/core/detection-rules/link-qr-code-with-phishing-disposition-in-img-or-pdf-8e8949f6
Link: QR Code with suspicious language (untrusted sender)
3mo ago
Jul 30th, 2025
Sublime Security
/feeds/core/detection-rules/link-qr-code-with-suspicious-language-untrusted-sender-25a84d1c
Attachment: HTML smuggling - QR Code with suspicious links
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d
Open redirect: typedrawers.com
5mo ago
May 23rd, 2025
Sublime Security
/feeds/core/detection-rules/open-redirect-typedrawerscom-158d9e95
Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender
9mo ago
Feb 3rd, 2025
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-pdf-attachment-leveraging-breach-data-from-freemail-sender-efb5a213
Link: QR code in EML attachment with credential phishing indicators
1y ago
Apr 25th, 2024
Sublime Security
/feeds/core/detection-rules/link-qr-code-in-eml-attachment-with-credential-phishing-indicators-9908ed3a