Question

Difficulty: MediumSocial Engineering Attacks and Vectors

An enterprise security operations center (SOC) detects that several remote staff members were redirected to a fraudulent Single Sign-On (SSO) credential-harvesting page after scanning a Quick Response (QR) code on physical flyers posted in a corporate office building. The flyers purported to contain a link to a mandatory employee workplace survey. Which social engineering attack vector best describes this technique?

  1. QuishingAnswer
  2. B
    Watering hole attack
  3. C
    Baiting
  4. D
    Spear phishing

Answer

Quishing (QR code phishing) is the social engineering vector that uses malicious QR codes to redirect victims to credential-harvesting or malicious websites.
The correct answer is quishing because the scenario describes an attack that uses Quick Response (QR) codes embedded on physical media to direct victims to a credential-harvesting webpage.

Step-by-Step Solution

1
Analyze the primary delivery medium in the security incident.
The attack relies on physical flyers featuring printed Quick Response (QR) codes.
Identifying the transmission vector (QR codes) is critical to categorizing the specific social engineering variant.
2
Evaluate the underlying objective of the attack mechanism.
Scanning the QR code redirects victims to a fake Single Sign-On portal to capture credentials.
This behavior combines traditional web-based credential harvesting with a mobile optical scan vector.
3
Match the observed indicators to formal security terminology.
Phishing conducted specifically through QR codes is defined as quishing.
Quishing accurately describes social engineering campaigns utilizing QR codes as the redirection vector.

Key Concept

Social Engineering Attack Vectors - Quishing
Rate this question