{"id":13983,"date":"2024-10-24T13:39:52","date_gmt":"2024-10-24T12:39:52","guid":{"rendered":"https:\/\/www.kappadata.pl\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/"},"modified":"2024-10-24T13:39:58","modified_gmt":"2024-10-24T12:39:58","slug":"clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security","status":"publish","type":"post","link":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/","title":{"rendered":"Clever phishing techniques: QR codes with ASCII and Blob URIs that bypass security"},"content":{"rendered":"<div class=\"wpb-content-wrapper\" id=\"wpb-content-root\"><p>[vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space][vc_column_text]<br \/>\nLearn how cybercriminals exploit QR codes.<br \/>\n[\/vc_column_text][vc_empty_space][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_separator type=&#8221;normal&#8221; color=&#8221;#a5a5a5&#8243;][vc_empty_space][vc_column_text]<\/p>\n<div class=\"flex max-w-full flex-col flex-grow\">\n<div class=\"min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words [.text-message+&amp;]:mt-5\" dir=\"auto\" data-message-author-role=\"assistant\" data-message-id=\"75f641ce-95d4-4a3c-93f5-4b8e83177dfd\" data-message-model-slug=\"gpt-4o\">\n<div class=\"flex w-full flex-col gap-1 empty:hidden first:pt-[3px]\">\n<div class=\"markdown prose w-full break-words dark:prose-invert light\">\n<p>Even the most carefully planned phishing campaigns fail if cybercriminals cannot bypass security measures.<\/p>\n<p>In a blog post on the Barracuda website, Ashitosh Deshnur (Associate Threat Analyst in the Threat Analyst Team at Barracuda Networks) presents two innovative security bypass techniques recently identified by Barracuda\u2019s threat analysts:<\/p>\n<p>The first technique involves QR codes that, instead of being a static image, are built using a combination of ASCII\/Unicode &#8220;block (\u2588)&#8221; characters. This tactic aims to prevent security software from extracting the malicious URL from the QR code.<\/p>\n<p>The second technique involves the use of &#8220;Blob&#8221; (binary large object) URIs (uniform resource identifiers), which access locally generated data within the browser, rather than relying on known malicious domains. These Blob URIs are created dynamically and can expire quickly, making them harder to track and analyze. Moreover, since some security mechanisms do not scrutinize Blob URIs as thoroughly as traditional HTTP or HTTPS links, phishing attacks using these URIs can bypass basic detection methods.<\/p>\n<h3>A New Generation of Malicious QR Codes<\/h3>\n<p>A year ago, phishing attacks using QR codes surged significantly. Barracuda data shows that approximately 1 in 20 mailboxes were targeted by QR code attacks in the last quarter of 2023.<\/p>\n<p>These attacks typically used static, image-based QR codes. Attackers embedded malicious links into these codes, encouraging users to scan them, which led to fake websites designed to resemble trusted services or applications.<\/p>\n<p>Security measures quickly adapted. Tools such as Optical Character Recognition (OCR) were able to extract, analyze, and block malicious URLs contained in QR codes.<\/p>\n<p>Barracuda&#8217;s threat analysts, during testing, identified a new generation of QR code phishing designed to bypass OCR-based defenses. In these attacks, the \u201cimage\u201d of the QR code is created using ASCII\/Unicode characters.<\/p>\n<p>In an email, such a QR code appears like a traditional QR code. However, to a typical OCR detection system, it seems meaningless.<\/p>\n<h4>Example 1<\/h4>\n<p>A phishing attack poses as a &#8220;Payroll and Benefits Registration&#8221; file, shared by an Administrator. When the unsuspecting recipient scans the QR code and clicks the link, they are redirected to a fake Microsoft login page.<\/p>\n<p>A closer inspection of the QR code reveals a line between each block. This happens because the QR code is not an image, but carefully crafted using the &#8220;full block&#8221; character, or &#8220;\u2588.&#8221;<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"mb-2 flex gap-3 empty:hidden -ml-2\">\n<div class=\"items-center justify-start rounded-xl p-1 flex\">\n<div class=\"flex items-center\">\n<div class=\"flex\"><\/div>\n<div class=\"flex items-center pb-0\"><span class=\"overflow-hidden text-clip whitespace-nowrap text-sm\">4o<\/span><\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>[\/vc_column_text][vc_empty_space]<div class=\"image_with_text\"><img decoding=\"async\" itemprop=\"image\" src=\"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Zrzut-ekranu-2024-10-11-095049.png\" alt=\"\" \/><h3  class=\"image_with_text_title\"><\/h3><span style=\"margin: 6px 0px;\" class=\"separator transparent\"><\/span><\/div>[vc_empty_space][vc_column_text]<\/p>\n<div class=\"flex-shrink-0 flex flex-col relative items-end\">\n<div>\n<div class=\"pt-0\">\n<div class=\"gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full\">\n<div class=\"relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"group\/conversation-turn relative flex w-full min-w-0 flex-col agent-turn\">\n<div class=\"flex-col gap-1 md:gap-3\">\n<div class=\"flex max-w-full flex-col flex-grow\">\n<div class=\"min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words [.text-message+&amp;]:mt-5\" dir=\"auto\" data-message-author-role=\"assistant\" data-message-id=\"3d05fb31-d443-4faf-8724-15027775ad8d\" data-message-model-slug=\"gpt-4o\">\n<div class=\"flex w-full flex-col gap-1 empty:hidden first:pt-[3px]\">\n<div class=\"markdown prose w-full break-words dark:prose-invert light\">\n<p>The QR code is a 49&#215;49 matrix composed of &#8220;full blocks&#8221; (\u2588).<\/p>\n<h3>What was done to make the QR code look convincing?<\/h3>\n<p>In areas where white spaces are required, a cascading style sheet (CSS) was used to make the color of the block text fully transparent, rendering them invisible.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>[\/vc_column_text][vc_empty_space]<div class=\"image_with_text\"><img decoding=\"async\" itemprop=\"image\" src=\"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Zrzut-ekranu-2024-10-11-095058.png\" alt=\"\" \/><h3  class=\"image_with_text_title\"><\/h3><span style=\"margin: 6px 0px;\" class=\"separator transparent\"><\/span><\/div>[vc_empty_space][vc_column_text]<\/p>\n<div class=\"flex-shrink-0 flex flex-col relative items-end\">\n<div>\n<div class=\"pt-0\">\n<div class=\"gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full\">\n<div class=\"relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"group\/conversation-turn relative flex w-full min-w-0 flex-col agent-turn\">\n<div class=\"flex-col gap-1 md:gap-3\">\n<div class=\"flex max-w-full flex-col flex-grow\">\n<div class=\"min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words [.text-message+&amp;]:mt-5\" dir=\"auto\" data-message-author-role=\"assistant\" data-message-id=\"3d05fb31-d443-4faf-8724-15027775ad8d\" data-message-model-slug=\"gpt-4o\">\n<div class=\"flex w-full flex-col gap-1 empty:hidden first:pt-[3px]\">\n<div class=\"markdown prose w-full break-words dark:prose-invert light\">\n<p>The QR code is a 49&#215;49 matrix composed of &#8220;full blocks&#8221; (\u2588).<\/p>\n<h3>What was done to make the QR code look convincing?<\/h3>\n<p>In areas where white spaces are required, a cascading style sheet (CSS) was used to make the color of the block text fully transparent, rendering them invisible.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>[\/vc_column_text][vc_empty_space]<div class=\"image_with_text\"><img decoding=\"async\" itemprop=\"image\" src=\"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Zrzut-ekranu-2024-10-11-095107.png\" alt=\"\" \/><h3  class=\"image_with_text_title\"><\/h3><span style=\"margin: 6px 0px;\" class=\"separator transparent\"><\/span><\/div>[vc_empty_space][vc_column_text]Example 2<br \/>\nIn this case, the attacker impersonates the courier company DHL and asks the recipient to fill out a form after scanning the QR code. Upon scanning the code, the victim is unexpectedly redirected to a phishing site.[\/vc_column_text][vc_empty_space]<div class=\"image_with_text\"><img decoding=\"async\" itemprop=\"image\" src=\"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Zrzut-ekranu-2024-10-11-095116.png\" alt=\"\" \/><h3  class=\"image_with_text_title\"><\/h3><span style=\"margin: 6px 0px;\" class=\"separator transparent\"><\/span><\/div>[vc_empty_space][vc_column_text]Another important point is that, in the case of HTML entities, each &#8220;block&#8221; can have multiple representations, and attackers can use single blocks or combinations of them to generate QR codes based on ASCII\/Unicode.<\/p>\n<p>All of this increases the possibilities for combinations, making ASCII-based QR codes particularly difficult to detect.<\/p>\n<p>Barracuda highlights that if security technologies identify the potential use of ASCII QR codes in a phishing attack, one of the simplest solutions is to take a screenshot of the phishing email and pass it to an OCR engine to read the URL hidden behind the QR code.<\/p>\n<h3>The Vast Potential of Blob URI to Bypass Security Measures<\/h3>\n<p>Blob URIs (also known as Blob URLs or Object URLs) are used by browsers to represent binary data or file-like objects (called Blobs) that are temporarily stored in the browser&#8217;s memory.<\/p>\n<p>Blob URIs allow web developers to work with binary data, such as images, videos, or files, without having to upload or download them from an external server.<\/p>\n<p>Because Blob URIs don\u2019t retrieve data from external URLs, traditional URL filtering and scanning tools may initially fail to recognize the content as malicious.<\/p>\n<p>Cybercriminals create phishing pages using Blob URIs, hoping that detection systems will have a harder time identifying and blocking malicious content.<\/p>\n<p>One of the first examples of a phishing attack using Blob URIs, identified by Barracuda\u2019s threat analysts, involved impersonating Capital One, encouraging users to click \u201cCheck your account.\u201d This redirected them to an intermediary phishing page that generated a Blob URI and quickly redirected the browser to the newly created address.[\/vc_column_text][vc_empty_space]<div class=\"image_with_text\"><img decoding=\"async\" itemprop=\"image\" src=\"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Zrzut-ekranu-2024-10-11-095125.png\" alt=\"\" \/><h3  class=\"image_with_text_title\"><\/h3><span style=\"margin: 6px 0px;\" class=\"separator transparent\"><\/span><\/div>[vc_empty_space][vc_column_text]What does a Blob URI do?<\/p>\n<p>It displays a fake Capital One login page to the victim.[\/vc_column_text][vc_empty_space]<div class=\"image_with_text\"><img decoding=\"async\" itemprop=\"image\" src=\"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Zrzut-ekranu-2024-10-11-095133.png\" alt=\"\" \/><h3  class=\"image_with_text_title\"><\/h3><span style=\"margin: 6px 0px;\" class=\"separator transparent\"><\/span><\/div>[vc_empty_space][vc_column_text]Threat analysts, during various tests, also noticed that the Blob URI technique was used in phishing attacks impersonating Chase and Air Canada.<\/p>\n<h3>Summary<\/h3>\n<p>Phishing techniques to evade detection have evolved significantly, posing an increasing threat to organizations. Cybercriminals are constantly improving their methods to bypass traditional security measures. As phishing attacks become more sophisticated, it is essential to implement multilayered defense strategies and promote a strong security culture.<\/p>\n<p>Megharaj Balaraddi, Associate Threat Analyst at Barracuda, also contributed to the research for this blog post. The original article can be found on the <strong>Barracuda Blog<\/strong>.[\/vc_column_text][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A new generation of malicious QR codes<br \/>\nA year ago, there was a sharp increase in phishing attacks based on QR codes. Barracuda data shows that about 1 in 20 mailboxes were targeted by QR code attacks in the last quarter of 2023.<br \/>\nThese attacks typically used static, image-based QR codes. Attackers embedded malicious links in the QR codes and encouraged users to scan them, leading them to fake websites designed to look like trusted services or applications.<\/p>\n","protected":false},"author":26,"featured_media":13953,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[168,75,71],"tags":[364,365,270,366,363,185,296,298],"class_list":["post-13983","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-barracuda-en","category-news","category-publications","tag-asciiqr-en","tag-bloburi-en","tag-cybersecurity-en","tag-networksecurity-en","tag-phishing-en","tag-cyberbezpieczenstwo-en","tag-hacker-attacks","tag-it-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>New phishing techniques: ASCII QR codes and Blob URIs \u2013 how attackers bypass security measures<\/title>\n<meta name=\"description\" content=\"A new generation of malicious QR codes A year ago, there was a significant increase in phishing attacks based on QR codes. Barracuda data shows that approximately 1 in 20 mailboxes were targeted by QR code attacks in the last quarter of 2023. These attacks typically used static, image-based QR codes. Attackers embedded malicious links in QR codes and encouraged users to scan them, leading them to fake websites designed to look like trusted services or applications\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New phishing techniques: ASCII QR codes and Blob URIs \u2013 how attackers bypass security measures\" \/>\n<meta property=\"og:description\" content=\"A new generation of malicious QR codes A year ago, there was a significant increase in phishing attacks based on QR codes. Barracuda data shows that approximately 1 in 20 mailboxes were targeted by QR code attacks in the last quarter of 2023. These attacks typically used static, image-based QR codes. Attackers embedded malicious links in QR codes and encouraged users to scan them, leading them to fake websites designed to look like trusted services or applications\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Kappa Data\" \/>\n<meta property=\"article:published_time\" content=\"2024-10-24T12:39:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-10-24T12:39:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Dolacz-do-nas-2024-4.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1228\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ola Serafin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ola Serafin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/\"},\"author\":{\"name\":\"Ola Serafin\",\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/#\\\/schema\\\/person\\\/d1b118980a9e892e9128e0dec942a300\"},\"headline\":\"Clever phishing techniques: QR codes with ASCII and Blob URIs that bypass security\",\"datePublished\":\"2024-10-24T12:39:52+00:00\",\"dateModified\":\"2024-10-24T12:39:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/\"},\"wordCount\":1123,\"image\":{\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.kappadata.pl\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/Dolacz-do-nas-2024-4.png\",\"keywords\":[\"#ASCIIQR\",\"#BlobURI\",\"#cybersecurity\",\"#NetworkSecurity\",\"#Phishing\",\"cyberbezpiecze\u0144stwo\",\"Hacker attacks\",\"IT security\"],\"articleSection\":[\"Barracuda\",\"News\",\"publications\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/\",\"url\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/\",\"name\":\"New phishing techniques: ASCII QR codes and Blob URIs \u2013 how attackers bypass security measures\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.kappadata.pl\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/Dolacz-do-nas-2024-4.png\",\"datePublished\":\"2024-10-24T12:39:52+00:00\",\"dateModified\":\"2024-10-24T12:39:58+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/#\\\/schema\\\/person\\\/d1b118980a9e892e9128e0dec942a300\"},\"description\":\"A new generation of malicious QR codes A year ago, there was a significant increase in phishing attacks based on QR codes. Barracuda data shows that approximately 1 in 20 mailboxes were targeted by QR code attacks in the last quarter of 2023. These attacks typically used static, image-based QR codes. Attackers embedded malicious links in QR codes and encouraged users to scan them, leading them to fake websites designed to look like trusted services or applications\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.kappadata.pl\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/Dolacz-do-nas-2024-4.png\",\"contentUrl\":\"https:\\\/\\\/www.kappadata.pl\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/Dolacz-do-nas-2024-4.png\",\"width\":1920,\"height\":1228},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Strona g\u0142\u00f3wna\",\"item\":\"https:\\\/\\\/www.kappadata.pl\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"publikacje\",\"item\":\"https:\\\/\\\/www.kappadata.pl\\\/category\\\/publikacje\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Clever phishing techniques: QR codes with ASCII and Blob URIs that bypass security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/#website\",\"url\":\"https:\\\/\\\/www.kappadata.pl\\\/\",\"name\":\"Kappa Data\",\"description\":\"The Art of IT-infrastucture, security and IoT distribution\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.kappadata.pl\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.kappadata.pl\\\/#\\\/schema\\\/person\\\/d1b118980a9e892e9128e0dec942a300\",\"name\":\"Ola Serafin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/46b33a839f63570fe8b8f59364eb7c69211298cafb1f9521405c3099f8cf7a09?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/46b33a839f63570fe8b8f59364eb7c69211298cafb1f9521405c3099f8cf7a09?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/46b33a839f63570fe8b8f59364eb7c69211298cafb1f9521405c3099f8cf7a09?s=96&d=mm&r=g\",\"caption\":\"Ola Serafin\"},\"sameAs\":[\"http:\\\/\\\/kappadata.pl\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New phishing techniques: ASCII QR codes and Blob URIs \u2013 how attackers bypass security measures","description":"A new generation of malicious QR codes A year ago, there was a significant increase in phishing attacks based on QR codes. Barracuda data shows that approximately 1 in 20 mailboxes were targeted by QR code attacks in the last quarter of 2023. These attacks typically used static, image-based QR codes. Attackers embedded malicious links in QR codes and encouraged users to scan them, leading them to fake websites designed to look like trusted services or applications","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/","og_locale":"en_US","og_type":"article","og_title":"New phishing techniques: ASCII QR codes and Blob URIs \u2013 how attackers bypass security measures","og_description":"A new generation of malicious QR codes A year ago, there was a significant increase in phishing attacks based on QR codes. Barracuda data shows that approximately 1 in 20 mailboxes were targeted by QR code attacks in the last quarter of 2023. These attacks typically used static, image-based QR codes. Attackers embedded malicious links in QR codes and encouraged users to scan them, leading them to fake websites designed to look like trusted services or applications","og_url":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/","og_site_name":"Kappa Data","article_published_time":"2024-10-24T12:39:52+00:00","article_modified_time":"2024-10-24T12:39:58+00:00","og_image":[{"width":1920,"height":1228,"url":"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Dolacz-do-nas-2024-4.png","type":"image\/png"}],"author":"Ola Serafin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ola Serafin","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/#article","isPartOf":{"@id":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/"},"author":{"name":"Ola Serafin","@id":"https:\/\/www.kappadata.pl\/#\/schema\/person\/d1b118980a9e892e9128e0dec942a300"},"headline":"Clever phishing techniques: QR codes with ASCII and Blob URIs that bypass security","datePublished":"2024-10-24T12:39:52+00:00","dateModified":"2024-10-24T12:39:58+00:00","mainEntityOfPage":{"@id":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/"},"wordCount":1123,"image":{"@id":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Dolacz-do-nas-2024-4.png","keywords":["#ASCIIQR","#BlobURI","#cybersecurity","#NetworkSecurity","#Phishing","cyberbezpiecze\u0144stwo","Hacker attacks","IT security"],"articleSection":["Barracuda","News","publications"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/","url":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/","name":"New phishing techniques: ASCII QR codes and Blob URIs \u2013 how attackers bypass security measures","isPartOf":{"@id":"https:\/\/www.kappadata.pl\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/#primaryimage"},"image":{"@id":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Dolacz-do-nas-2024-4.png","datePublished":"2024-10-24T12:39:52+00:00","dateModified":"2024-10-24T12:39:58+00:00","author":{"@id":"https:\/\/www.kappadata.pl\/#\/schema\/person\/d1b118980a9e892e9128e0dec942a300"},"description":"A new generation of malicious QR codes A year ago, there was a significant increase in phishing attacks based on QR codes. Barracuda data shows that approximately 1 in 20 mailboxes were targeted by QR code attacks in the last quarter of 2023. These attacks typically used static, image-based QR codes. Attackers embedded malicious links in QR codes and encouraged users to scan them, leading them to fake websites designed to look like trusted services or applications","breadcrumb":{"@id":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/#primaryimage","url":"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Dolacz-do-nas-2024-4.png","contentUrl":"https:\/\/www.kappadata.pl\/wp-content\/uploads\/2024\/10\/Dolacz-do-nas-2024-4.png","width":1920,"height":1228},{"@type":"BreadcrumbList","@id":"https:\/\/www.kappadata.pl\/en\/clever-phishing-techniques-qr-codes-with-ascii-and-blob-uris-that-bypass-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Strona g\u0142\u00f3wna","item":"https:\/\/www.kappadata.pl\/en\/"},{"@type":"ListItem","position":2,"name":"publikacje","item":"https:\/\/www.kappadata.pl\/category\/publikacje\/"},{"@type":"ListItem","position":3,"name":"Clever phishing techniques: QR codes with ASCII and Blob URIs that bypass security"}]},{"@type":"WebSite","@id":"https:\/\/www.kappadata.pl\/#website","url":"https:\/\/www.kappadata.pl\/","name":"Kappa Data","description":"The Art of IT-infrastucture, security and IoT distribution","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.kappadata.pl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.kappadata.pl\/#\/schema\/person\/d1b118980a9e892e9128e0dec942a300","name":"Ola Serafin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/46b33a839f63570fe8b8f59364eb7c69211298cafb1f9521405c3099f8cf7a09?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/46b33a839f63570fe8b8f59364eb7c69211298cafb1f9521405c3099f8cf7a09?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/46b33a839f63570fe8b8f59364eb7c69211298cafb1f9521405c3099f8cf7a09?s=96&d=mm&r=g","caption":"Ola Serafin"},"sameAs":["http:\/\/kappadata.pl"]}]}},"_links":{"self":[{"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/posts\/13983","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/users\/26"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/comments?post=13983"}],"version-history":[{"count":2,"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/posts\/13983\/revisions"}],"predecessor-version":[{"id":13985,"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/posts\/13983\/revisions\/13985"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/media\/13953"}],"wp:attachment":[{"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/media?parent=13983"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/categories?post=13983"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kappadata.pl\/en\/wp-json\/wp\/v2\/tags?post=13983"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}