Tricked by the Square: Investigating the Rise and Reach of Quishing Attacks

Swaraj Tandel, Jiya Chordiya, Pratidnya S. Hegde Patil · International Journal for Research in Applied Science and Engineering Technology · 2025

Abstract: Quick Response (QR) codes have become ubiquitous in modern digital interactions, facilitating seamless transactions, authentication, and information sharing. However, their widespread adoption has introduced a new cybersecurity threat - Quishing (QR Code Phishing) where attackers exploit QR codes to deceive users into scanning malicious payloads or visiting fraudulent websites. Unlike traditional phishing, Quishing bypasses conventional defences by leveraging the inherent opacity of QR codes, automated scanning behaviours, and weak API security in QR-driven workflows. This paper investigates the technical and psychological mechanisms behind Quishing, analysing attack vectors such as URL obfuscation, session hijacking, and physical QR tampering in public spaces. Additionally, it evaluates human vulnerabilities, including environmental trust bias and habitual scanning tendencies, which contribute to high victimization rates. To counter these threats, we propose a multi-layered defence framework incorporating cryptographic QR authentication, API security hardening, intelligent scanning platforms, and user awareness initiatives. Emerging technologies like blockchain verification, AI-driven anomaly detection, and federated threat intelligence are also explored as future-proof solutions. Our findings highlight the urgent need for standardized security protocols, behavioural interventions, and adaptive defences to mitigate Quishing risks in an increasingly QR-dependent digital ecosystem.

Read the paper · More papers on PaperTik