Hackers often abuse weaponized Word docs, as they can contain macros that contain or exploit flaws inside those Word files to run destructive code upon being opened by the intended victims.
It enables an attacker to employ this tool to deliver a payload to a target system or unauthorized access to a targeted system by simply sending the target an innocent file with a Word extension, most of the time evading the security systems.
Cybersecurity researchers at Cyble discovered that hackers have been actively using weaponized Word documents in QR code phishing attacks.
QR code phishing attacks have surged recently, exploiting the technology’s all-presence and users’ familiarity to redirect them to credential-stealing sites.
Scan Your Business Email Inbox to Find Advanced Email Threats - Try AI-Powered Free Threat Scan
In 2024, such attacks increased by 22% compared to late 2023, with 89.3% aimed at stealing credentials per Abnormal Security.
Threat actors embed malicious QR codes in emails, documents, and public places, using them to mask destinations.
A recent campaign used Microsoft Word docs impersonating Chinese government agencies with undetected QR codes prompting users to authenticate for fake subsidies, aiming to harvest financial data like in a January 2023 incident documented by Fortinet.
The malicious QR code redirects victims to a domain generated by a DGA, hosting a phishing site impersonating China’s Ministry of Human Resources.
This domain resolves to IP 20.2.161.134, which hosts several other subdomains (.tiozl.cn and .zcyyl.com) linked to the massive phishing campaign, reads Cyble report.
The SSH host key fingerprint ties this IP to 17 others in Hong Kong’s AS8075, bearing similar phishing URLs. Landing pages display fake labor subsidy lures, then harvest entered personal details like names and national IDs from victims.
Finally, the phishing site prompts victims to enter bank card numbers, phone numbers, and balances on behalf of false verification, which enables unauthorized transactions after they have harvested names and IDs.
This loading screen is followed by a prompt for withdrawal passwords used to make domestic credit card payments.
Attackers can consequently conduct unauthorized transactions with the full details of a card, and these passwords can lead to financial losses.
In other words, this advanced QR code phishing scam capitalizes on trusted technology and tricks to steal financial information, effectively highlighting the mounting danger necessitating increased alertness.
Here below we have mentioned all the recommendations:-
Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…