Threat actors have launched a phishing campaign that leverages a novel technique to evade email security controls by rendering QR codes using HTML tables instead of traditional image files. The QR codes are constructed from hundreds of small table cells, each styled with black or white backgrounds to mimic the appearance of a standard QR code, but without embedding an actual image. This approach allows the QR code to be scanned by mobile devices while bypassing many email security gateways and QR inspection engines, which typically focus on detecting image-based QR codes. The phishing emails are minimalistic, containing only a short lure and a single, compressed QR code block that encourages recipients to scan it.
The QR codes in these campaigns redirect users to malicious subdomains, often crafted to appear legitimate by incorporating the recipient's own domain name in the URL path. Security researchers observed that this technique was actively used in phishing messages sent between December 22 and December 26, and noted that the HTML-based QR code structure is not new but remains relatively unknown and effective at evading detection. The use of HTML tables for QR code rendering highlights a blind spot in current email security solutions and demonstrates the ongoing evolution of phishing tactics to circumvent established defenses.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-07, the SANS Internet Storm Center published analysis of the campaign, highlighting that HTML table-based QR codes can bypass security tools focused on image-based QR detection. The reporting recommended improved technical controls, including analysis of dense HTML tables, along with continued user awareness training.
Between 2025-12-22 and 2025-12-26, attackers ran a phishing campaign that rendered QR codes as HTML tables instead of image files inside emails. The QR codes directed recipients to malicious lidoustoo[.]click subdomains, often with URLs tailored to the target's email address or domain to appear more legitimate.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.