[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Phishing on the Edge of the Web and Mobile Using QR Codes

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 15 min read  
Related Products  
[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Diva-Oriane Marty](https://unit42.paloaltonetworks.com/author/diva-oriane-marty/)
  * [Shehroze Farooqi](https://unit42.paloaltonetworks.com/author/shehroze-farooqi/)
  * [Alex Starov](https://unit42.paloaltonetworks.com/author/alex-starov/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:February 13, 2026

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/)
  * [QR Codes](https://unit42.paloaltonetworks.com/tag/qr-codes/)
  * [Social engineering](https://unit42.paloaltonetworks.com/tag/social-engineering/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/qr-codes-as-attack-vector/?pdf=download&lg=en&_wpnonce=1f7a0335d5 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/qr-codes-as-attack-vector/?pdf=print&lg=en&_wpnonce=1f7a0335d5 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Phishing%20on%20the%20Edge%20of%20the%20Web%20and%20Mobile%20Using%20QR%20Codes&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fqr-codes-as-attack-vector%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fqr-codes-as-attack-vector%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fqr-codes-as-attack-vector%2F&title=Phishing%20on%20the%20Edge%20of%20the%20Web%20and%20Mobile%20Using%20QR%20Codes "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fqr-codes-as-attack-vector%2F&text=Phishing%20on%20the%20Edge%20of%20the%20Web%20and%20Mobile%20Using%20QR%20Codes "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fqr-codes-as-attack-vector%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Phishing%20on%20the%20Edge%20of%20the%20Web%20and%20Mobile%20Using%20QR%20Codes%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fqr-codes-as-attack-vector%2F "Share in Mastodon")

## Executive Summary

This article explores the misuse of QR codes in today's threat landscape, covering three areas of concern:

* QR codes using URL shorteners to disguise malicious destinations
* QR codes using in-app deep links to steal account credentials and take control of a victim's apps
* QR codes attempting to bypass app store security by linking to direct downloads of malicious apps

With QR codes a notable presence in our everyday lives, some people instinctively scan them without hesitation. But QR codes are also a vector for attack. QR codes enable attackers to bypass organizational security by exploiting the weaker controls of personal mobile devices. By doing this, they can trick users into scanning codes and interacting with malicious destinations outside the corporate security perimeter.

Over the past several months, we have tracked campaigns that used QR codes for phishing (known as quishing) and scams. Our telemetry reveals an average of over 11,000 detections of malicious QR codes each day. Investigating these detections, we found that attackers are leveraging QR code shorteners, in-app deep links and direct downloads to bypass people's awareness and security controls.

In addition to mass campaigns, we see attackers using QR codes for highly targeted messenger app phishing, such as [targeting Ukrainian Signal users](https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger) in the context of the Russia-Ukraine war. These findings necessitate further analysis of deep links and QR code data.

Palo Alto Networks customers are better protected from the threats described in this article through the following products and services:

* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration)
* [Prisma Browser](https://docs.paloaltonetworks.com/prisma-access-browser)

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**QR Codes**](https://unit42.paloaltonetworks.com/tag/qr-codes/), [**Phishing**](https://unit42.paloaltonetworks.com/tag/phishing/), **[Social Engineering](https://unit42.paloaltonetworks.com/tag/social-engineering/)** |
|----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## Phishing QR Codes Not New, but a Growing Threat

QR codes are not a new technology, but [their prevalence](https://codebroker.com/the-rise-of-qr-codes-in-the-united-states-a-trend-driven-transformation/) has increased with the push for contactless interactions, especially [during the initial emergency phase of the coronavirus pandemic](https://www.lithiosapps.com/blog/rise-and-fall-of-qr-codes-and-how-a-pandemic-revived-them). QR codes allow companies to interact seamlessly with their customer base for payments, enabling customers to join rewards programs and sign up for apps or mailing services. People have grown used to QR codes in daily life, and often scan them without sufficient caution, increasing their susceptibility to attacks.

The popularity of QR codes has led to their use by attackers. In our offline web crawlers, we currently find an average of 75,000 detections of QR codes each day, with 15% of these pages containing QR codes leading to malicious links. This represents an average of over 11,000 detections of malicious QR code use each day.

### **Problem of Evasive QR Code Redirects**

We looked beyond the recognized risks of QR codes. While straightforward QR code web-based attacks remain a threat, our focus shifted to understanding how attackers are leveraging the following trends to remain evasive to both victims and security controls:

* [QR code shorteners](#post-172806-_n4f31vojng4h)
* [In-app deep links](#post-172806-_61lur7d6vrni) (special URLs that allow people to open specific content within a mobile app)
* [Direct app file downloads](#post-172806-_10nvxr8wfwtr)

These tactics represent an evolution in QR code-based attacks that security teams need to address.

Previous [Unit 42 research](https://unit42.paloaltonetworks.com/qr-code-phishing/) has covered several key attack vectors for phishing QR codes hosted on documents, which are also relevant when hosted on websites. Attacks through these vectors can be effective for several reasons including:

* Lower user vigilance
* Security solutions having difficulty extracting URLs embedded in QR codes
* Complex redirection chains that obscure final destinations
* Weaker security controls on personal mobile devices
* Hosting on otherwise legitimate-looking pages

Building upon this threat model, in-app deep links allow the attacker to target specific apps and trigger specific behavior (Figure 1).
![QR Code Threat Model illustrating a threat scenario. It features a flow of actions: 1. Attacker creates a malicious QR code on a benign webpage. 2. Victim scans QR code on the web page with a mobile device. 3. Attacker gains access to victim's mobile device through the app. Includes icons, directional arrows, and text descriptions explaining each step.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-525372-172806-1.png) Figure 1. QR code threat model.

QR codes on websites need to be analyzed by security crawlers and other security solutions. To close this security gap, specific QR code detection techniques must be deployed to analyze the various data types stored in QR codes:

* Standard HTTPS URLs
* Deep links
* Non-URL content (e.g., JSON, plaintext)

### **Key Definitions**

**QR code shorteners**are services that combine a URL shortener with a QR code generator to create a shorter, more scannable QR code that links to a long URL. These shorteners offer benefits such as reducing the size of the QR code, allowing attackers to change the destination URL later, and tracking scan data in a single dashboard.

**In-app deep links** are [hyperlinks that direct visitors to a specific screen or content within a mobile app](https://developer.android.com/training/app-links/create-deeplinks). In-app deep links can use both custom URL schemes (i.e., sms:+1234567890:Hello, tg\[:\]//login?token= ) or standard web URLs (i.e., hxxps\[:\]//wa\[.\]me/settings/linked\_devices#) that the operating system redirects to the app.

Figure 2 shows an example that displays a phishing site impersonating a job match and training program website that hosts a payment in-app deep link. Deep links are often used to improve user experience by reducing the number of steps to access specific content from external sources like emails, social media, authentication tokens or ads.
![Phishing Host Page - Job Match \& Training Program. The background is blue with a navigation menu listing "About Us," "Our Services," and "Contact Us." There is a QR code on the right labeled "Payment QR Code Landing Page" with a URL highlighted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-527541-172806-2.png) Figure 2. QR code in-app deep link example.

## The Stealth Factor: QR Code Shorteners

Attackers use QR code shorteners to mask malicious destinations. QR code shorteners convert a static image into a dynamic endpoint. Consequently, the attacker can change the redirect destination at will.

The attacker is also able to leverage the good reputation of QR code shortener services to evade detection of malicious activity. Even security-conscious people who check the URL preview before scanning cannot determine the final destination when presented with shortened links. This technique effectively prevents targets from being aware of potential threats until after the malicious payload has been delivered.

Our previous article has already talked about the [risk of URL shorteners](https://unit42.paloaltonetworks.com/why-innocent-clicks-dont-exist-in-cybersecurity/) more broadly. However, the combination of a QR code and URL shortener is even more likely to bypass scrutiny.

### **Steady Increase in QR Code Shortener Traffic**

We have seen QR code shortener traffic grow steadily over the past three years (Figure 3).
![Graph showing QR code shortener traffic from 2023 to 2025 for qrc.cc, qrco.de, me-qr.com, qr.io, qrly.com, qrfy.io, qrfy.me, gbt-qr.com, qn.ee, and qrs.ly. The x-axis represents time, and the y-axis represents count, ranging from 0 to 300,000. Traffic generally trends upward over this period.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/chart-12.png) Figure 3. QR code shortener traffic trends, 2023-2025.

We see a steady increase of QR code shortener traffic in our telemetry. This includes a 55% increase from the first half of 2023 to the first half of 2024 and a 44% increase from the first half of 2024 to the first half of 2025. This data is based on the following popular QR code shortener services:

* qrcc\[.\]io
* qrco\[.\]de
* me-qr\[.\]com
* qr\[.\]io
* qrfy\[.\]com
* qrfy\[.\]io
* get-qr\[.\]com
* qr\[.\]ne, qrs\[.\]ly

### **Most Misused QR Code Shortener Services**

Our telemetry reveals that qrco\[.\]de, me-qr\[.\]com and qrs\[.\]ly are the most used QR code shorteners. Compared to the top QR code shorteners mentioned in the[Anti-Phishing Working Group (APWG) phishing trends report \[PDF\]](https://docs.apwg.org/reports/apwg_trends_report_q1_2025.pdf), qrs\[.\]ly is a notable new addition as the QR code shortener used in 7.3% of the malicious URLs observed.

### **Targeted Industries**

Financial services was the most impacted industry when considering compromised QR code shorteners, accounting for 29% of this type of attack. This is followed by high tech (19%) and wholesale and retail (14%). Significantly, QR code shorteners for financial services make up only 4.8% of this type of traffic as a whole. This makes the high percentage of compromised QR code shorteners for financial services even more striking as shown in Figure 4
![Bar chart showing the percentage of compromised QR code shorteners (in red) and total QR code shorteners (in yellow) across various industries. Industries on the x-axis include Financial Services, High Technology, Wholesale and Retail, Insurance, Transportation and Logistics, Education, Professional and Legal Services, Manufacturing, Aerospace and Defense, and State and Local Government. The y-axis represents percentages, ranging from 0 to 30. A blue trend line curves downward from Financial Services to State and Local Government.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/chart-13.png) Figure 4. This chart illustrates the contrast between the total QR code shorteners we observed in traffic, by industry, and the number of compromised QR code shorteners, by industry.

### **Example of a Phishing Attack Misusing a QR Code Shortener**

The webpage shown in Figure 5 is a popular file-sharing platform containing a QR code that appears to imitate a school by including its logo. Upon analysis, we found that it is a QR code shortener that first redirects to a CAPTCHA page and then lands on a phishing page that impersonates Outlook hosted on cdnimg.jeayacrai\[.\]in\[.\]net. After a few days, the URL from this QR code no longer worked, illustrating how QR code shorteners are often ephemeral and can quickly cease redirecting to the original malicious endpoint.
![The image depicts a phishing scam example. On the left, there's an email imitating a school, containing a phishing QR code leading to a malicious site. On the right, the landing page replicates a Microsoft Outlook login page, with URLs pointing to suspicious domains.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-538939-172806-5.png) Figure 5. Malicious QR code shortener example.

## In-App Deep Links Vulnerabilities: More Than Just Web Browsing

Modern mobile devices support a wide range of QR code actions beyond simple web browsing. The distribution of in-app deep links in QR codes is an understudied area despite its exploitability. In-app deep links account for about three percent of the QR codes in our telemetry. Attackers can either misuse app functionality (e.g., adding a trusted device, or sending a payment), or push malicious content to those apps (such as, adding malicious links to calendar invites).

Defenders face a challenge in detecting malicious in-app deep links embedded in QR codes because the activity generated by these links is often invisible to standard web crawlers. Effective detection necessitates a mobile sandbox environment with the specific app installed to properly observe and analyze this activity. Custom in-app deep links lack standardization across applications. This makes identifying malicious signals difficult to generalize, often requiring individualized investigation for each case.

Both iOS and Android devices can process QR codes with in-app deep links that have direct app integration. We categorize in-app deep links as those that apply to the following types of apps:

* Social media and communications
* App stores
* Payment
* System utilities (e.g., Wi-Fi, contacts, calendar, telephone, email, SMS, navigation)

The three most popular custom app URLs that we found were for Telegram, XHS Discover (RedNote) and Line, which respectively account for 44.7%, 1.8% and 0.8% of in-app deep links. As we discuss later, attackers commonly misuse Telegram and Line.

### Attack Scenarios

In-app deep links enable additional cross-device interactions, creating new attack scenarios via QR codes.

Table 1 lists some examples of the attack chain scenarios possible through in-app deep links.

|--------------------------|---------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Attack** **Name**      | **Deep Link Category**          | **Description**                                                                                                                                                                                                                                                                     | **Example (QR Code Content)**                                                                                                                                                                                                                                           |
| Financial fraud          | Payment                         | Direct access to payment applications with pre-filled recipient information                                                                                                                                                                                                         | bitcoin:**attackers\_address**                                                                                                                                                                                                                                           |
| Account Takeover         | Social Media and Communications | Directs the victim to authenticate the attacker into the victim's account                                                                                                                                                                                                           | **Attacker's website hosts** : tg\[:\]//login?token=xxxx                                                                                                                                                                                                                |
| Embedding Malicious URLs | Communications, Other Apps      | Attackers can embed malicious URLs in emails or text messages to be sent from the victim's device, saved into a file, etc.                                                                                                                                                          | mailto\[:\]receive@mail\[.\]com?subject=Request%5D\&body=Please%20visit%20this%20website%20**www.malicious-url\[.\]com**  {info-here : **www.malicious-url\[.\]com** }                                                                                            |
| Calendar poisoning       | System utilities                | Malicious meeting links added to calendars that redirect victims to phishing sites when they attempt to join meetings,  [Malicious files](https://www.trincoll.edu/trinitytoday/announcements/phishing-alert-calendar-based-phishing-attack/) added to a calendar invite      | BEGIN:VCALENDAR VERSION:2.0 BEGIN:VEVENT SUMMARY:Team Lunch \& Planning Session DTSTART:20251205T120000 DTEND:20251205T130000 LOCATION: **www.phishing-meeting-link-url\[.\]com**  DESCRIPTION:Discuss Q4 results and plan for Q1 goals. END:VEVENT END:VCALENDAR |
| Contact poisoning        | System utilities                | Embedding malicious URLs or [fake contacts](https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-malware-is-adding-fake-contacts-to-your-phone-while-draining-bank-accounts) within contact information that activate when victims interact with saved contacts | BEGIN:VCARD  N:First Name, Last Name TITLE:Dep. xxx TEL:+1 000-000-000 EMAIL:**attack-email@xx\[.\]com** URL:**malicious-website\[.\]com** END:VCARD                                                                                                              |
| Rogue Wifi networks      | System utilities                | Automatically connecting victims to attacker-controlled networks                                                                                                                                                                                                                    | WIFI:T:WPA;S\*\*:attacker-network-name\*\* ;P:password;H:false;                                                                                                                                                                                                             |

Table 1. Attack scenarios involving in-app deep links.

Many of these attack scenarios involve embedding malicious URLs into specific data entries stored in mobile apps. Figure 6 illustrates this for contact poisoning, where a malicious URL is embedded in a saved contact card.
![This image shows a comparison between a vCard file on the left and a contact entry on a smartphone on the right. The vCard includes fields like full name, title, phone number, email, and a website URL labeled as "malicious-website.com." The smartphone contact entry reflects the same details, highlighting the email as "attack-email@xx.com" and the website URL "malicious-website.com" in red. The interface resembles a typical smartphone contacts app.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-542075-172806-6.png) Figure 6. Contact poisoning attack scenario.

Some of the scenarios described in Table 1 were not observed in our data collection, while others were. The ones not observed are plausible, but hypothetical scenarios. We will further discuss the scenarios observed in our data collection below.

### Current Attack Trends and Examples

#### Financial Fraud In-App Deep Links

Financial in-app deep links represent a significant financial risk to potential victims. QR codes are commonly used in legitimate business transactions to facilitate payments, making it straightforward for attackers to misuse this trusted interaction through phishing schemes. We observed legitimate in-app deep links from popular payment apps such as:

* WeChat Pay
* Alipay
* Bitcoin
* Ethereum
* LitCoin
* Metamask
* Trust (wallet)

The familiarity and trust people have with payment-related QR codes create an ideal environment for social engineering attacks, where malicious QR codes can closely mimic legitimate payment requests. Phishing campaigns using pressure tactics can manipulate people into making quick payments.

Below, we share a few examples where an attacker attempts to trigger a financial transaction using a QR code. Figure 7 includes two examples. The first example is a phishing campaign claiming easy returns on investment, asking for an initial payment through a Bitcoin in-app deep link. The second example is a hacking for hire service advertising and providing easy payment with a WeChat payment in-app deep link.
![The image shows two sections with text and QR codes. The left section has a green header titled "Payment Address," details for Bitcoin payments, and a phishing QR code with a deep link starting with "1w2Xw...". The right section has a blue background with Chinese text about a "Hackers online 24/7 order-taking website" and customer service, and includes a phishing QR code with a link.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-543976-172806-7.png) Figure 7. Examples of malicious financial in-app deep links.

Figure 8 illustrates another get-rich-quick phishing scheme that requests an initial payment through a popular cryptocurrency wallet via a QR code with an in-app deep link.
![The image shows a webpage for "Solulu Liquidity Pool Plan" with a phishing QR code pop-up for connecting via MetaMask. There is an image of digital currencies and a colorful wallet icon with money and a credit card.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-546151-172806-8.png) Figure 8. QR code phishing scheme that uses a popular cryptocurrency wallet.

#### Messenger Account Takeover Through In-App Deep Links

Account takeovers through in-app deep links appear to be a significant phishing vector for messaging and social media sites. Telegram, in particular, was the most prominent application identified in our analysis that uses custom in-app deep links. We found over 35,000 QR codes that contain Telegram in-app deep links such as tg\[:\]//login or tg\[:\]//resolve and we observed multiple instances where attackers exploited these links to compromise accounts.

We saw three kinds of Telegram in-app deep links:

* Login
* Resolve
* Proxy

Login accounted for 97% of the Telegram in-app deep links observed. Login grants the QR code creator authorization to access your account.

Previous reporting of [Telegram in-app deep link scams](https://www.criminalip.io/knowledge-hub/blog/29770) warns about these account takeover attacks. Roughly one out of every five host pages with a login Telegram in-app deep link is malicious, based on our conservative estimate.

Figure 9 includes two examples of such Telegram login scams. However, while Telegram is the most popular, attackers are also targeting other popular communication apps.
![A collage illustrating Telegram in-app QR code linking. The left image shows a Telegram chat screen with a QR code labeled "Open In Telegram" and a URL for a deep link. The top center text mentions the widespread use of this Telegram feature, highlighting its popularity. On the right, a colorful online gaming promotional banner is displayed.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-548400-172806-9.png) Figure 9. Example of a QR code designed to give an attacker full access to the device and account owner's Telegram.

Figure 10 shows an example of a QR code containing an in-app deep link that requests authorization to a target's Line account. This would allow attackers to send Line messages under the device and account owner's name. Of note, Line has since deprecated this in-app deep link, and the link will now result in an error.

![QR code for the LINE app on the left. Directions to scan the code with the app are included below. On the right, a verification screen showing country or region as Japan, with several permission toggles.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-550837-172806-10.png) Figure 10. Example of a QR code for a Line account takeover.

Figure 11 shows an example of a QR code containing an in-app deep link that requests authorization to access a target's Signal account.
![This image shows a webpage and a smartphone screen displaying instructions on linking a device to the Signal app. The webpage includes the URL with a red QR code in-app deep link. The smartphone screen displays a phishing QR code and a pop-up message confirming the option to link a Signal device.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-552838-172806-11.png) Figure 11. Example of a QR code for a Signal account takeover.

Figure 12 shows an example of a QR code containing an in-app deep link that requests authorization to access a target's WhatsApp account.
![Comparison between a benign host page for WhatsApp Web login and a phishing QR code from an in-app deep link. The top left shows the normal WhatsApp Web authentication login page with a QR code and URL displayed. The bottom left displays a different QR code with a text indicating it is from an in-app deep link. Both sections have explanatory text highlighting differences.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-555000-172806-12.png) Figure 12. Example of a QR code for a WhatsApp account takeover.

In addition to mass phishing campaigns, there's a clear trend toward more focused attacks aimed at stealing Signal credentials. For instance, the Google Threat Intelligence Group (GTIG) [has documented increased efforts](https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger) by Russia state-aligned actors to compromise Signal Messenger accounts. These attacks frequently misuse Signal's [feature to link devices](https://support.signal.org/hc/en-us/articles/360007320551-Linked-Devices) with malicious QR codes.

Many of these campaigns have targeted Ukraine in the context of the Russia-Ukraine war. In July 2024, the CERT-UA reported on several threat groups, such as [UAC-0185](https://cert.gov.ua/article/6281632) (aka UNC4221), that have specifically targeted messenger accounts.

Our researchers continue to observe new malicious domains targeting Ukrainian Signal users, including snitch.open-group\[.\]site and similar variations. After linking a new session to Signal accounts, the attackers can exfiltrate message history and other account information. We have reported discovered information to our Ukrainian cybersecurity partners.

Figure 13 shows a QR code from a campaign targeting Ukraine-based Signal accounts.
![A phishing QR code is displayed on the left, labeled "Login using Signal." On the right, there's an app interface on a tablet or phone showing a prompt titled "Link a Signal device?" with an option to "Continue." An outline of Ukraine connects the two elements, illustrating a linking process.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-556985-172806-13.png) Figure 13. QR code from a campaign targeting Ukraine-based Signal accounts.

## Bypassing App Store Security: Direct App Downloads

QR codes are widely used for easy downloading of files and applications. Attackers can exploit this convenience to trick victims into downloading malicious content or installing harmful mobile applications.

Major app stores impose strict security and compliance guidelines to limit the distribution of harmful apps. However, attackers may circumvent these security measures by distributing links to unreviewed Android Package Kit (APK) files hosted on their own servers via QR codes.

Our investigation identified 59,000 detections of host pages distributing a total of 1,457 distinct APK files directly through QR codes, without going through any app store. Notable examples of these distributed APKs are listed below.

### Gambling/Casino App Downloads

Gambling and casino games websites are distributing their apps through APK files in QR codes.

Figures 14-16 illustrate some examples of such host pages. They are all hosted by many different domains and request certain Android permissions that could be concerning to people.

Figure 14 shows an ad for a popular game that includes a QR code, which redirects the victim to another QR code to download [a game app](https://www.virustotal.com/gui/file/bb2fd45eb1d4a0df344f68e1d00c34254f43de29234e1c1370ba3ea799b4bf80) named yicai.apk from ​​f9999\[.\]app. This QR code is hosted on 10,022 unique URLs.

The app requests read and write permissions to the device's external storage and camera. It also requests install packages permissions.
![Gambling game distribution campaign through a QR code. At the top, there is a webpage featuring logos and graphics with a QR code linked to a URL. Below, a sequence of smartphone screenshots displays the download and installation process of the app, highlighting the appearance of the app icon on a home screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-559097-172806-14.png) Figure 14. First example of a gambling game distribution campaign through a QR code.

Figure 14 shows an ad for [another game](https://www.virustotal.com/gui/file/8ad89eca9d1c0f83498678abd8f5c933ae341fcd600cf0c4a664db632fed84c4) hosted on 9,161 unique URLs. The URL used in Figure 15 is hxxps\[:\]//pyreneesakbash\[.\]com/m-nagapoker/android.html. The file for the game is named NagaPocker.apk, and it requests write to external storage and internet permissions.
![The image shows an online casino website interface featuring a central figure at a card table holding playing cards and poker chips. In the lower left corner a phishing QR code is highlighted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-561355-172806-15.png) Figure 15. Second example of a gambling game distribution campaign through a QR code.

Figure 16 shows [an app](https://www.virustotal.com/gui/file/623b9d775c035965da9ad17b682c2b80d5e0d324e485aaff052e5953181675a0) distributed through two different pages. Named app-u7cp-release.apk, the app requests:

* Access to coarse location
* Access to fine location
* Background location
* Read and write access to external storage
* Read phone state
* Camera permissions

![Two website screenshots side by side. The left screenshot displays a phishing QR code and a list on a white background, with a red arrow pointing to a URL at the top, highlighting "app-u7cp-release.apk" in red. The right screenshot shows a colorful banner over a webpage layout with another red arrow at the top pointing to a URL, highlighting "app-u7cp-release.apk" in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-563806-172806-16.png) Figure 16. Two different pages with QR codes leading to the same app.

Warnings from [Trustwave](https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/unmasking-malicious-apks-android-malware-blending-click-fraud-and-credential-theft/) about malicious APK files highlight that these types of gambling and betting apps expose victims to harmful activity, such as:

* Excessive advertising
* Theft of personal data
* Theft of funds
* Hidden fees
* Subscriptions

These apps provide financial incentives for engagement, prolonging the life of such scams. Allowing victims to download apps directly and bypassing official app stores enables attackers to circumvent app verification procedures.

Many campaigns hosting QR codes that pointed to a given APK file did so across numerous domains. The apps request suspicious Android permissions, most notably write external storage, camera and access fine location. These permissions could allow intentional data exfiltration, accidental data leakage and surveillance. The aggressive distribution across many different host pages, stealthy methods and excessive permissions suggest malicious intent.

### Other Malicious App Downloads

Though gambling apps account for a large portion of the QR codes distributing APK files, QR codes also distribute other kinds of suspicious apps. Figure 17 illustrates two examples.
![The image displays two app pages side by side. The left side features a website for a phone optimization app with a blue background and QR codes. The right side shows a webpage for a social media platform for education, with "k12" in the URL, and includes text and images on a white background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/word-image-566960-172806-17.png) Figure 17. Examples of QR code with malicious app downloads.

The [first example](https://www.virustotal.com/gui/file/409fbd7b6cb101b338be48ca57891fc984b16113f0f874e8200bc743b6fc9d0f) is a phone optimization app named ludashi\_home.apk. It requests the following permissions:

* Recording audio
* Reading battery status
* Reading phone state
* Accessing the camera
* Reading and writing to external storage
* Authenticating accounts
* Clearing the app cache
* Installing packages permissions

The [second example](https://www.virustotal.com/gui/file/b4b6fc59b1fa55fe942cfa357b1ecaf48314679ff4ddc19c64a279e2a5a3c8c7) is a social network app for educators named k12sns.apk. This app also requests several different types of permissions:

* Accessing the internet
* Reading logs
* Waking the lock
* Reading the phone state
* Writing to external storage

Several vendors detect these apps as suspicious or malicious, and they extract sensitive information from the device they are installed on. For example, the phone optimization app can take on certain behaviors like authenticating accounts and installing further packages, which attackers can misuse for malicious gains.

## Conclusion

The attack scenarios and variety of examples we've discovered illustrate the extensive potential and existing prevalence of QR code misuse. The fundamental challenges of this type of misuse are user awareness and lack of visibility from current detection systems.

Most people scanning QR codes don't anticipate the broad range of device functions that can be triggered from in-app deep links or unexpected endpoints from QR code shorteners. This expectation mismatch creates a significant security weak spot that attackers can actively exploit.

User education remains critical --- people need to understand that QR codes can do much more than simply open webpages.

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

Customers using [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) and [Prisma Browser](https://docs.paloaltonetworks.com/prisma-access-browser) (with Advanced Web Protection) are better protected against various QR code attacks. Our detectors analyze QR code landing pages and deep links.

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 000 800 050 45107
* South Korea: +82.080.467.8774

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Acknowledgements

The authors would like to thank Bradley Duncan and Billy Melicher for the thorough technical review of the article. We would also like to thank the editorial team including Samantha Stallings and Lysa Myers for the assistance with improving and publishing this article.

## Indicators of Compromise

Examples of URLs for QR code shorteners:

* hxxps\[:\]//www.dropbox\[.\]com/scl/fi/7e8xqrcxgzftrk61omgn0/Presentation.pptx?rlkey=xgk24xllhh4qqv1li2ifd3e3s\&st=xvtu5b7y\&dl=0
* hxxps\[:\]//qrco\[.\]de/bgP6vx
* hxxps\[:\]//cdnimg.jeayacrai\[.\]in\[.\]net/qY42h5ei3SBo9ZmvO!/

Examples of URLs for financial scams:

* hxxp\[:\]//kccomputech\[.\]in/babukh1513273
* upi://pay?pa=Q573631163@ybl\&pn=PhonePeMerchant\&mc=0000\&mode=02\&purpose=00
* hxxps\[:\]//20.217.81\[.\]20
* bitcoin:12wXzmwak8LJ88e1ejupY3brfQi43xdDhb
* hxxps\[:\]//csdh.wangzhan\[.\]mobi
* wxp\[:\]//f2f04lGLqnDoxxeZnftA79yXXU-BeXrgkdYL
* solulu\[.\]vip
* metamask\[:\]//connect?channelId=d92099ec-28e3-4eed-97e8-3c40c656f555\&v=2\&comm=socket\&pubkey=021f24e23edc0cbb73440dc2ac94b5a458371cc7c9ce8551b1b68db2196443c2ba\&t=q\&originatorInfo=eyJ1cmwiOiJodHRwOi8vc29sdWx1LnZpcCIsInRpdGxlIjoid2FnbWkiLCJpY29uIjoiaHR0cDovL3NvbHVsdS52aXAvbG9nby5wbmciLCJzY2hlbWUiOiIiLCJhcGlWZXJzaW9uIjoiMC4zMy4xIiwiZGFwcElkIjoic29sdWx1LnZpcCIsImFub25JZCI6Ijk1ZDcyY2M3LTYwYWYtNGI5Yi1hZTJiLTk4YmE4MDcxZmQwZiIsInBsYXRmb3JtIjoid2ViLWRlc2t0b3AiLCJzb3VyY2UiOiJ3YWdtaSJ9

Examples of URLs and domains for Telegram account takeover:

* hxxps\[:\]//fable.tele-tale\[.\]cn
* tg\[:\]//login?token=AQJgx85oZgPcBRoIg76p-8BBy4nB4Wpel-PvZ8Og7t\_--A
* Olb228hoki\[.\]live
* radenspinrtp\[.\]cloud
* bostonsportsthenandnow\[.\]com
* slotolb228\[.\]com
* tg\[:\]//login?token=AQI-jOVkNxCqKYy-wB6VFz-nE-eo-l-tFtgZ3VPshaKJ0A

Examples of URLs and domains for Signal account takeover:

* hxxp\[:\]//www.sgnl-web\[.\]org-status.nl/
* hxxps\[:\]//signal-qr\[.\]org/chatZGtqZmpic2l1NDkzdWpka25zamRucDJ1MDllamtmOThyNGltdmZkZw==/ty62i
* signal.skyriver\[.\]ch

Examples of phishing domains targeting Ukrainian Signal users:

* snitch.open-group\[.\]site
* gui.snitch-dev\[.\]site
* gui.dev-snitch\[.\]site
* gui.snitch-dev\[.\]xyz
* gui.dev-snitch\[.\]xyz
* gui.snitch-dev\[.\]online
* gui.dev-snitch\[.\]online
* gui.dev-snitch\[.\]site
* gui.dev-snitch\[.\]cloud
* snitch-dev\[.\]space
* gui-snitch\[.\]online
* gui-grafit\[.\]online
* kropyva-group\[.\]online

Examples of URLs for Line account takeover:

* hxxps\[:\]//link.members-ms\[.\]jp/view/clickCount?cst\_id=000000000003690\&msg\_id=0000000000000000000000833677\&deli\_date=20251029\&redirect\_uri=hxxps%3A%2F%2Fliff.line.me%2F2007686667-M9geAqrB%3Fid%3D5%3FROUTE\_KBN%3D12\&msg\_type=1\&sec\_msg=BtBnJY9kxxWnP%2BQt3ycGtVVhajc%3D\&sec\_date=zVK0EnCA1F8siaD0nf4Nsq1VRlc%3D\&sec\_uri=P85jU5m9ynEk1wr9ltPW%2Fh%2BJrxE%3D\&sec\_type=XWWoEGkCR%2BDRAsxfdW4dQHnr%2FbI%3D
* line\[:\]//app/2007686667-M9geAqrB?liff.state=%3Fid%3D5%253FROUTE\_KBN%253D12%26cst\_id%3D000000000003690%26msg\_id%3D0000000000000000000000833677%26deli\_date%3D20251029\&liff.referrer=hxxps%3A%2F%2Fbing\[.\]com%2F\&liff.source=lp\_qr

Examples of URLs and domains for WhatsApp account takeover:

* hxxps\[:\]//kzeva2010\[.\]sbs/MZApUU1aJ3LSYi86IrAZ
* hxxps\[:\]//wa\[.\]me/settings/linked\_devices#2@vxFKwMU92ToQ60n6gPIw/SLkNcoYVu1XKW+/zMiBEuslO63jfBCCZX/f1mOrkxrAqkp4DaSzq5MX7CcvOJqrNDSJQRLKgXP7K2A=,tZrifOdd4aLBy9nrncQVsa0WqVcYmJnFSs8nEpt3URs=,DfpvHVSe6SmZWxAgVdYXsYz2FsD7DQ3NgmGybCNMHHY=,Ipp5goLgYXXn+7Swuw+pGX77EFECRemAHS5gfOJE7G4=,1
* hxxps\[:\]//xlq.wpybta\[.\]icu
* hxxps\[:\]//wa\[.\]me/settings/linked\_devices#2@8zRSshgXZVfdYcvUvycaOQJlQBcjUDomiqdxC8uQEowH5TQLr/P+1QbxvrXPV4tKg23mqzQeMpPRp3ofr4mePrur/YN4ztk6fWY=,FaknzsibNU+yi9cvuQKDgI3eBh+KEY2TQHqilwZ+KRs=,Rpz7L5S/72o1Ust4Y6CZ3tC7gf6yQvJdd80IFbZzdiw=,eZyTFPAbZWlFUXjGbrvBCM4ApoYT50kFXQb+/cTMzPw=,1
* wswwc\[.\]icu
* awawc\[.\]icu
* ve1edm\[.\]cc
* ve2edm\[.\]cc
* weppf\[.\]icu

Examples of URLs hosting APK files for gambling game

* hxxps\[:\]//gricanjolt\[.\]com?r=aHR0cHM6Ly9mOTk5OS5hcHA=1
* hxxps\[:\]//pyreneesakbash\[.\]com/m-nagapoker/android\[.\]html
* hxxps\[:\]//resourcepro.tycheint\[.\]com/yicai\[.\]apk
* hxxps\[:\]//90999.fdjk34sddsf90999\[.\]cc/xincai\[.\]apk
* hxxps\[:\]//gld45a.cqxqlsz\[.\]com/fusion2023/android/app-u7cp-release\[.\]apk
* hxxps\[:\]//azojwdsj.xinchaoshan\[.\]com/fusion2023/android/app-u7cp-release\[.\]apk
* hxxp\[:\]//www.ludashi\[.\]com/cms/android/special/download\[.\]html hxxp\[:\]//t.k12\[.\]com\[.\]cn/k12sns\[.\]apk

## Additional Resources

* [Deep Link](https://developer.android.com/training/app-links/create-deeplinks)- Android, Google
* [Evolution of Sophisticated Phishing Tactics: The QR Code Phenomenon](https://unit42.paloaltonetworks.com/qr-code-phishing/) -- Unit 42, Palo Alto Networks
* [Myth Busting: Why "Innocent Clicks" Don't Exist in Cybersecurity](https://unit42.paloaltonetworks.com/why-innocent-clicks-dont-exist-in-cybersecurity/) -- Unit 42, Palo Alto Networks
* [Phishing Activity Trends Report Q1 2025 \[PDF\]](https://docs.apwg.org/reports/apwg_trends_report_q1_2025.pdf) -- Anti-Phishing Working Group (APWG)
* [Telegram QR Phishing Threat: Account Takeover with a Single Scan](https://blog.criminalip.io/2025/09/17/telegram-qr-phishing/) - CIP blog, Criminal IP
* [Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger](https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger) -- Google Threat Intelligence Group (GITG), Google
* [Unmasking Malicious APKs: Android Malware Blending Click Fraud and Credential Theft](https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/unmasking-malicious-apks-android-malware-blending-click-fraud-and-credential-theft/) -- Trustwave, A LevelBlue Company
* [​​Dangerous new Android malware adds fake contacts to your phone while draining bank accounts --- how to stay safe](https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-malware-is-adding-fake-contacts-to-your-phone-while-draining-bank-accounts) -- Tom's Guide
* [Phishing Alert: Calendar-Based Phishing Attack](https://www.trincoll.edu/trinitytoday/announcements/phishing-alert-calendar-based-phishing-attack/) -- Trinity College
* [Unit 42 Cryptocurrency Scam Chatbot Activity](https://www.linkedin.com/posts/unit42_cryptocurrency-scam-chatbot-activity-7389779414445826048-L0Rh/) -- Unit 42, Palo Alto Networks
  Back to top

### Tags

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")
* [QR Codes](https://unit42.paloaltonetworks.com/tag/qr-codes/ "QR Codes")
* [Social engineering](https://unit42.paloaltonetworks.com/tag/social-engineering/ "social engineering")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Nation-State Actors Exploit Notepad++ Supply Chain](https://unit42.paloaltonetworks.com/notepad-infrastructure-compromise/ "Nation-State Actors Exploit Notepad++ Supply Chain")

### Table of Contents

* 

### Related Articles

* [Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "article - table of contents")
* [Inside the Modern SOC: The Identity Front Door](https://unit42.paloaltonetworks.com/soc-identity-front-door/ "article - table of contents")
* [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
