An enterprise security operations center (SOC) detects that several remote staff members were redirected to a fraudulent Single Sign-On (SSO) credential-harvesting page after scanning a Quick Response (QR) code on physical flyers posted in a corporate office building. The flyers purported to contain a link to a mandatory employee workplace survey. Which social engineering attack vector best describes this technique?
- QuishingAnswer
- BWatering hole attack
- CBaiting
- DSpear phishing
Answer
Quishing (QR code phishing) is the social engineering vector that uses malicious QR codes to redirect victims to credential-harvesting or malicious websites.
The correct answer is quishing because the scenario describes an attack that uses Quick Response (QR) codes embedded on physical media to direct victims to a credential-harvesting webpage.
Step-by-Step Solution
Key Concept
Social Engineering Attack Vectors - Quishing