ANDROID owners have been urged to avoid scanning malicious QR codes that can steal your money.

After the COVID-19 pandemic hit, threat actors increasingly began using QR codes to scam people.

Android owners have been urged to avoid scanning malicious QR codes

1

Android owners have been urged to avoid scanning malicious QR codesCredit: Getty

A new report by cybersecurity firm Perception Point found that 1 out of 11 of all phishing attempts are carried out through a QR code.

This represents a 2200% increase from 1 out of 250 phishing attempts that were previously reported.

The rise in QR code phishing, also known as quishing, is no coincidence, experts said.

Cybercriminals know that most smartphone owners have no idea what quishing is and they’re looking to exploit this.

HOW DOES QUISHING WORK?

QR codes work by embedding instructions into a black-and-white dot-based image.

So when a smartphone camera, app, or QR code scanning device scans the QR code, the scan then translates the data into human-readable information.

However, in a scam, the fraudsters will embed a malicious QR code into a legitimate-looking email or stick it somewhere in public.

In turn, malicious QR codes (also known as malware) can infiltrate your device and steal sensitive information, such as banking account logins.

Most read in News Tech

“Through quishing, attackers have managed to bypass most email security vendors, compounding the new tactic with deceptive social engineering,” Perception Point writes in its report.

“What makes the use of QR codes in emails difficult to detect is that the content and intent of QR codes are not immediately apparent,” it continued.

This, when coupled with convincing language, impersonation of trusted companies, and a sense of urgency, can easily manipulate users into falling for a quishing scam.

HOW TO PROTECT YOURSELF

There are several ways to mitigate your risk of QR phishing. Perception Point recommends first and foremost, knowing your stuff. 

Second, you will want to use a DNS filter that can break the phishing cycle.

DNS filters do this by stopping users from navigating to a malware-laden website.

Third, it helps to apply email filters, which use multiple avenues to catch difficult-to-detect phishing messages.

Having an anti-malware or anti-virus enabled on your device can also greatly help.

This post first appeared on Thesun.co.uk

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Facebook ‘overpaid in data settlement to avoid naming Zuckerberg’

Lawsuit alleges settlement in Cambridge Analytica case driven by desire to protect…

Mark Kelly’s Been To Space. Can He Make it to Capitol Hill?

But even though Glenn hadn’t spent time in office, he did have…

Stunning view from SpaceX capsule as Elon Musk’s Inspiration4 blasts further than Jeff Bezos managed

ELON MUSK’S SpaceX firm has tweeted footage of the first Earth views…

Maquette Goes Big on Metaphor but Light on Real Emotion

How late is too late? It’s the question every finite relationship asks…