Gabagool is a phishing-as-a-service (PhaaS) kit used for QR-code phishing ("quishing") campaigns. Reported behavior includes splitting a QR code into two separate images within phishing emails so automated email security scanners may interpret them as benign fragments, while a recipient viewing the message can still scan the combined code with a mobile device. Barracuda researchers reported this technique was used to evade detection and direct victims to credential-harvesting pages, including fake Microsoft account login pages. Observed lure themes included targeted password-reset scams and activity likely tied to conversation hijacking. The content specifically identifies Gabagool as a phishing kit rather than traditional malware, and associates it with credential theft via phishing emails delivered through QR-code-based social engineering.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-as-a-service kit that uses split QR-code images to evade email security scanning; when scanned on mobile, it directs victims to fake Microsoft login pages to steal credentials.
A phishing-as-a-service kit used to deliver QR-code-based phishing (“quishing”) by splitting a QR code into multiple image fragments to evade email security scanning and redirect victims to credential-harvesting pages (e.g., fake Microsoft login).
A phishing-as-a-service kit used to deliver QR-code-based phishing (“quishing”) by splitting a QR code into multiple image fragments to evade email security scanning and redirect victims to credential-harvesting pages (e.g., fake Microsoft login).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.