Attackers are building scannable QR codes from colored HTML table cells, rather than embedded images or attachments, to bypass email controls that extract and inspect conventional QR-code images. The emails can render a valid code even where remote images are disabled, directing recipients—often from a managed workstation to a mobile device—to credential-harvesting, session-theft, payment-fraud, or malware-delivery sites.
The technique, identified by PhishU Framework, exploits gaps in defenses that do not render and visually inspect full email content. Organizations should detect QR-like visual patterns and unusually dense HTML markup, decode and assess resulting destinations, maintain remote-image blocking, apply post-delivery link protection, and test controls through authorized phishing simulations. HTML-email rendering differs across clients; reported Unicode block-character QR variants have displayed unreliably in Gmail mobile, while table-cell implementations are intended to provide more consistent rendering.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The FBI warned that North Korea-aligned Kimsuky used malicious QR codes in spearphishing campaigns targeting organizations in the United States.
An attempted version of the technique using Unicode block characters reportedly rendered unreliably in Gmail mobile, where character stretching prevented consistent QR-code construction. The HTML-table method was discussed as a more viable approach despite the challenges of inconsistent HTML-email rendering across clients.
PhishU Framework identified a quishing method that constructs scannable QR codes from colored HTML-table cells or text-like markup in email bodies, rather than embedded image files. The technique can evade controls that only extract and inspect conventional QR-code images and can direct recipients to phishing sites or other hostile destinations.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.