ESET Warns of Rising Quishing Attacks Using Malicious QR Codes
Cybersecurity firm ESET warns of a sharp increase in quishing attacks using malicious QR codes to bypass email filters and target corporate mobile devices.

Cybersecurity firm ESET has issued a warning regarding the rapid surge of quishing, a specialized form of phishing attack utilizing malicious QR codes. The technique relies on the ubiquitous nature of QR codes in daily life, ranging from restaurant menus to digital payments, which leads users to scan them without hesitation.
The Mechanics of Quishing
Unlike traditional phishing emails that contain clickable links or malicious file attachments leading to fraudulent websites, quishing conceals the target URL inside a 2D matrix barcode. This method poses significant challenges for both unsuspecting users and conventional email security filters, as the address does not appear as readable plain text. Attackers frequently embed these codes inside PDF or JPEG documents attached to correspondence.
The danger becomes significantly greater the moment an employee scans the code using a smartphone. Instead of remaining within the secure corporate desktop environment, the user transitions to a mobile device that is often less protected or entirely unmanaged by the organization, explains Or Isaac, support manager at Comsecure, ESET's exclusive distributor in Israel.
Advanced Threats and State-Sponsored Attacks
Beyond simple credential harvesting to steal usernames and passwords, threat actors utilize quishing to intercept authentication tokens, redirect targets to unofficial app stores for malware downloads, or manipulate legitimate payment applications with pre-populated recipient details.
-
Credential theft and session hijacking via rogue login portals.
-
Distribution of malicious applications bypassing official app stores.
-
Fraudulent payment redirection using legitimate financial apps.
Furthermore, state-sponsored cyber espionage groups have adopted the vector. In January 2026, the FBI issued an advisory warning that the North Korean threat group Kimsuky deployed QR codes in targeted spear-phishing campaigns against research institutes, academic facilities, and government bodies globally, enticing victims to scan codes under the guise of surveys or secure document drives.
Recommended Defense Strategies
Security experts recommend incorporating QR-based simulations into employee awareness training, avoiding the scanning of unsolicited codes, and independently verifying unusual requests through trusted channels. Additionally, organizations should deploy mobile security solutions, enforce phishing-resistant multi-factor authentication, and ensure all operating systems remain regularly updated.





