Hackers Can Phish with PLAINTEXT QR Codes

Hackers Can Phish with PLAINTEXT QR Codes

Source: YouTube · John Hammond · published Mar 26, 2024 · 25:29

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video demonstrates a proof-of-concept method for bypassing email image filters by generating functional QR codes using plain text Unicode characters 0:00.

Key Takeaways:
• Threat actors often use QR codes for phishing, but since security administrators block HTML images, creating QR codes in plain text offers a potential bypass 0:29.
• A Python script utilizing the Pillow library analyzes a standard QR code image to calculate the bounding box and block size by reading grayscale pixel values 5:51.
• The script converts the image data into a 2D array of 1s and 0s, representing black and white blocks, which are then rendered using Unicode block characters 16:07.
• Initial attempts failed in email clients due to uneven font spacing, requiring the replacement of standard spaces with a light shade Unicode character 19:08 21:06.
• The final plain text QR code successfully renders in clients like Outlook and is scannable by mobile devices, demonstrating a viable social engineering vector 23:19.

While visually unappealing, this technique highlights a potential security gap where plain text characters can be used to evade standard email filters.

Sources:

  • 0:00 Introduction to QR codes in phishing
  • 5:51 Python script setup and bounding box calculation
  • 16:07 Rendering QR code with Unicode characters
  • 19:08 Testing in email clients and encountering font issues
  • 21:06(https://www.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

have you ever seen an email that looks like this an email that includes a QR code and encourages you to scan it to either sign in or access some online account or service sometimes these are legitimate say from Microsoft 365 or even Discord uses it not in an email but some form or fashion or a QR code is relied upon to accomplish something maybe that's set up two factor or multiactor authentication and look thread actors hackers and adversaries acknowledge this and they try to capitalize on it to even send some fishing campaigns some social engineering emails and see who might fall for a lore in a hook where a QR code is included now when we get to chat with it administrators CIS admins or whatever practitioners who say well I wouldn't get that email because our email filter will see the a…