spot_img

Date:

Share:

Kaspersky warns of attackers using text symbols to form malicious QR codes

QR codes embedded in emails have long been a tool for phishing and scams, and back in the second half of 2025 there was a fivefold surge in QR phishing attacks detected by Kaspersky. Now Kaspersky researchers have identified a new phishing tactic in which attackers construct QR codes using text characters rather than traditional images. This method allows such malicious QR codes to bypass many email security solutions that rely on image scanning or link detection.

Early computers were incapable of rendering true graphics, and images on them were composed entirely of text characters. Historically this was done with symbols from the ASCII (American Standard Code for Information Interchange) character set, introduced in 1963. Images created using this technique were called ASCII graphics. Later other character sets (like Unicode) were also utilised to create images, but the term ASCII graphics remained.

In the 2000s, spam senders already used images built from text symbols. By using text-based graphics instead of embedded images, attackers tried to avoid detection mechanisms that analyse pictures for hidden URLs.

With ASCII graphics used to create QR codes, the phishing scheme follows a familiar pattern as with QR codes in images which Kaspersky described earlier. Victims receive an email allegedly coming from a business partner, claiming to include a confidential document for signature via DocuSign. The message instructs the recipient to scan a QR code to access the document, leading to a fake website where corporate credentials are requested. With the QR code laid out in text characters, many protective solutions would fail to identify any suspicious links.

“We have previously seen phishers try to avoid link scanning by hiding URLs in images. Now they are attempting to evade image-based scanning by returning to text – this time to render a QR code. Any instance where a QR code prompts someone to enter corporate credentials on a mobile device should raise immediate suspicion. When the QR code is formed using textual ASCII art, it is almost certainly a phishing attempt or a lure to a malicious URL. This trick has only one purpose: bypassing security technologies,” comments Roman Dedenok, Anti-Spam Expert at Kaspersky.

To defend against this threat, Kaspersky recommends deploying a proven mail server security solution such as Kaspersky Security for Mail Server that provides secure corporate email exchange, countering spam, email-borne infections, all forms of phishing, business email compromise (BEC), QR code attacks, and other threats.

spot_img
spot_img

━ More like this

South African banking leaders see AI agents as industry’s greatest vulnerability in next year

Artificial intelligence is rapidly reshaping the fraud landscape, and South African banking leaders appear among the most concerned globally. In a new survey of 1,440 fraud...

The cybersecurity reset: Why last year’s playbook is obsolete

For South African IT teams in 2026, cyber defence is akin to defending a goal line with an outdated playbook. The formations are familiar, the...

Kaspersky has discovered a new corporate phishing technique using a popular AI web development platform

Kaspersky has discovered that attackers have begun exploiting another legitimate service for malicious purposes – this time it is Tencent EdgeOne Pages, a platform...

Kaspersky warns of “grey” scam websites exploiting user trust

Recent research by Kaspersky has shown that the so-called “grey” websites repeatedly target all world regions, and this may be driving both financial loss...

Kaspersky ICS CERT: The beginning of 2026 showed an increase in cyberattacks on the manufacturing sector

According to a new Kaspersky ICS CERT report, in Q1 2026 the percentage of industrial control systems (ICS) on which malicious objects were blocked...
spot_img