
07.08.2026 quishingphishingmobile forensicsincident response
QR codes used to be a harmless fixture of restaurant menus and event posters. Since 2025 they have become one of the most effective phishing delivery mechanisms in the threat landscape, with malicious QR code emails surging 587% in the first half of 2025 compared to the same period in 2024. For investigators, this creates a structural problem: the attack originates on a corporate endpoint but physically jumps to a different device — usually a personal smartphone sitting outside the reach of EDR and network monitoring.
The mechanic is deceptively simple and now has its own MITRE ATT&CK entry: quishing embeds malicious URLs inside QR codes to force victims to pivot from their corporate endpoint to a mobile device, bypassing traditional email security controls, and is tracked by MITRE ATT&CK as T1660. For classic incident response, this means the evidence chain breaks exactly where the actual compromise happens. Coalition frames the issue precisely — because QR codes are scanned using smartphones, they bypass security controls like endpoint detection and response. Corporate infrastructure logs the inbound email flawlessly but has no visibility into the scan event itself, the mobile browser context, or the credentials entered afterward.
North Korea’s Kimsuky group illustrates just how targeted this technique has become. According to an FBI flash advisory, Kimsuky actors have targeted think tanks, academic institutions, and both U.S. and foreign government entities with embedded QR codes in spearphishing campaigns since 2025. In one documented case, Kimsuky actors sent a strategic advisory firm a spearphishing email in June 2025 inviting recipients to a non-existent conference, with a QR code directing them to a registration landing page. In parallel, ReversingLabs tracked a broader multi-wave operation: between February 26 and March 18, 2026, a threat actor delivered 28 phishing emails directly to enterprise inboxes across three waves. A recurring lure pattern involves impersonating trusted document platforms: these QR code phishing attacks are spoofed to look like electronic signature documents generated through Docusign or Adobe Acrobat Sign, though they are not legitimate documents from either service. The trendline confirms the shift: quishing accounted for 12% of all phishing attacks globally in 2025, up from just 0.8% in 2021.
A solid reconstruction requires stitching together data sources that are usually managed by entirely separate teams. On the gateway side, detection has caught up somewhat: Proofpoint uses optical character recognition to extract the link from the QR code and then conducts regular reputation and blocklist checks — these scan results are a valuable, frequently overlooked log source for tracing the campaign’s origin. But the real break happens on the mobile device, where MDM platforms provide the critical bridge: mobile device management technologies can monitor malicious activity on mobile devices and help track long-term phishing campaigns. Equally important is what happens to harvested credentials afterward: stolen mobile credentials are routinely replayed against cloud services, enabling account takeover, lateral movement, and follow-on spearphishing campaigns from compromised mailboxes. For IR teams, that means conditional access logs, token replay indicators, and mobile browser history now belong in every quishing playbook — not just the email header.
Quishing is a textbook case of attackers exploiting the forensic blind spot between device ecosystems. Any incident response process that still treats endpoint types as strictly separate silos will remain blind exactly where the actual compromise step takes place.
← Back to overview