UPDATED 12:00 EST / NOVEMBER 14 2023

SECURITY

SlashNext’s latest service offers protection against QR code phishing

Phishing protection company SlashNext Inc. today announced the launch of a new service to protect against malicious QR code threats such as quishing, QRLJacking and other scams.

The new SlashNext QR Code Phishing Protection service is claimed to be the first security solution to offer protection against multi-channel quishing, for QR code phishing, that blocks malicious QR codes in email, mobile, web and messaging channels such as Slack, iMessage and Microsoft Teams.

SlashNext argues that its new service differs from other security solutions that aim to address quishing and QRLJacking, or QR code login hijacking, by leveraging computer vision and a new QR Code natural language processing classifier that protects users from more than just credential quishing. The new service can detect malicious intent in both the QR code and the accompanying message to deliver accurate protection against QR code-based attacks.

QR codes first became well-known in the West through contact tracing during the COVID-19 pandemic, although they have been used far longer in the U.S. and even more in countries such as China. Anything that becomes popular naturally attracts scammers and other miscreants, which is most definitely true with QR codes.

A report published by SlashNext in October found that an increasing number of cybercriminals are exploiting the widespread use of QR codes to launch sophisticated phishing attacks. Quishing has become particularly common as cybercriminals target unsuspecting users who, trusting the legitimacy of QR codes, can be redirected to malicious sites aimed at stealing sensitive data or tricked into inadvertently downloading malware onto their devices.

Also highlighted in the report is the more niche threat of QRLJacking, which involves attackers exploiting the “login with QR code” feature adopted by numerous apps and websites. A typical QRLJacking involves tricking a user into scanning a controlled QR code, leading to session hijacking.

“In recent months, quishing and QRLJacking have contributed to the huge growth we have observed in phishing,” said SlashNext Chief Executive Patrick Harr. “Without proper protection, it is nearly impossible for the average user to distinguish a legitimate QR code from a malicious code.”

“It is unreasonable to expect employees and everyday users to avoid QR codes altogether when they are quickly becoming ubiquitous in many legitimate service industries and for login purposes,” Harr added. “However, the cybercriminals know this as well, which is why we will only see an increased reliance on quishing and QRLJacking as attack techniques.”

Image: DALL-E 3

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.