Tactic or Technique: QR code

QR codes are those square barcodes you scan with your phone to open a link. You’ve probably used them at restaurants, parking meters, or on event flyers. Attackers take advantage of how common and trusted they’ve become by hiding malicious links inside them. When scanned, a QR code can send you to a phishing site or install malware on your device.
These codes often appear in emails, attachments, or printed materials and are designed to look harmless. Some use redirect chains that pass through a URL shortener or compromised site before landing on the actual payload, making them harder to detect.
Because you can’t see where a QR code leads before scanning, and many scans happen on personal phones without enterprise protections, attackers get a reliable way to steal credentials, install malware, or access corporate systems through unmanaged devices.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: SVG files with evasion elements
4d ago
May 8th, 2026
Sublime Security
Brand impersonation: DocuSign with embedded QR code
8d ago
May 4th, 2026
Sublime Security
Attachment: Fake voicemail via PDF
12d ago
Apr 30th, 2026
Sublime Security
Attachment: QR code with userinfo portion
12d ago
Apr 30th, 2026
Sublime Security
Attachment: QR code link with base64-encoded recipient address
13d ago
Apr 29th, 2026
Sublime Security
QR Code with suspicious indicators
20d ago
Apr 22nd, 2026
Sublime Security
Brand impersonation: Adobe (QR code)
22d ago
Apr 20th, 2026
Sublime Security
Attachment: ICS calendar file with QR code containing recipient email address
22d ago
Apr 20th, 2026
Sublime Security
Attachment: PDF with split QR code
27d ago
Apr 15th, 2026
Sublime Security
Attachment: Compensation review lure with QR code
28d ago
Apr 14th, 2026
Sublime Security
Attachment: EML with QR code redirecting to Cloudflare challenges
1mo ago
Apr 1st, 2026
Sublime Security
Service abuse: Monday.com infrastructure with phishing intent
2mo ago
Mar 9th, 2026
Sublime Security
Attachment: PDF with recipient email in link
2mo ago
Mar 3rd, 2026
Sublime Security
Attachment: QR code with recipient targeting and special characters
2mo ago
Feb 21st, 2026
Sublime Security
Attachment: QR code with suspicious URL patterns in EML file
2mo ago
Feb 21st, 2026
Sublime Security
Attachment: QR code with encoded recipient targeting and redirect indicators
3mo ago
Jan 30th, 2026
Sublime Security
Attachment: QR code with credential phishing indicators
3mo ago
Jan 12th, 2026
Sublime Security
Brand impersonation: Microsoft (QR code)
3mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling - QR Code with suspicious links
3mo ago
Jan 12th, 2026
Sublime Security
Link: QR code in EML attachment with credential phishing indicators
5mo ago
Dec 2nd, 2025
Sublime Security