QuishFire: QR Code Phishing (Quishing) Simulation¶
Platform Feature:
QuishFire
UI Location:Main Navigation > Attack Vector Arsenal > QuishFire (/quishfire)
Threat Forge Scenarios:Threat Forge > QR Scenarios (/qr-scenarios)
Telemetry & Reports:Posture Reports > QuishFire Simulation Reports
1. Executive Summary & Value Proposition¶
Quishing (QR Code Phishing) is one of the fastest-growing social engineering tactics worldwide. Attackers embed malicious URLs inside Quick Response (QR) codes, completely bypassing Secure Email Gateways (SEGs) and transferring the victim from a protected corporate desktop to an unmanaged personal smartphone.
QuishFire, SimuPhish’s specialized QR code phishing simulation module, trains employees to recognize QR deception, measures cross-device vulnerability, and inoculates organizations against mobile credential harvesting.
2. The Threat Landscape & The Real-World Problem Solved¶
- The Problem: Traditional Secure Email Gateways inspect plain text, HTML links, and file attachments. When an attacker sends an email containing an embedded QR code, traditional mail filters see only a harmless image.
- The Device Shift Attack: By scanning the QR code with their mobile phone, the employee moves the transaction off the corporate network and corporate-monitored workstation onto their personal device, where endpoint detection (EDR), browser protection, and corporate DNS filtering are completely absent.
- Explosive Growth: Security research reports show that QR code phishing incidents increased by over 580% year-over-year, targeting corporate 2FA registrations, parking passes, open enrollment, and cafeteria menus.
3. How It Works (The User Journey)¶
The Administrator Experience¶
- Campaign Configuration: Navigate to
Attack Vector Arsenal > QuishFire (/quishfire)and select target groups from active directories or specific departments (e.g., Sales, HR, Executives). - AI-Assisted QR Pretext Generation: Choose from dynamic templates under
Threat Forge > QR Scenarios(e.g., "Mandatory Authenticator App Migration", "Annual Compensation Review", "Office Wi-Fi Re-Authentication") or generate new pretext lures using AI. - Dynamic QR Encoding: QuishFire automatically generates unique, high-resolution QR codes embedded with cryptographic tracking tokens per recipient.
- Cross-Device Tracking: Administrators receive distinct analytics showing:
- How many employees opened the email on desktop.
- How many employees took out their smartphones and scanned the QR code.
- How many entered mock credentials on the mobile landing page.
The Employee Experience¶
- The employee opens an email instructing them to scan a QR code using their mobile phone camera.
- When scanned, the phone’s browser opens a mobile-optimized mock login page.
- If mock credentials are submitted, the employee is immediately presented with a mobile-friendly Teachable Moment (Oops Page) explaining:
- Why corporate services will never ask you to scan a QR code to verify login credentials.
- How to spot illegitimate QR codes on screens, posters, and emails.
graph LR
Desktop["Employee views email on Corporate PC"] -->|Scans QR Code with Phone| Mobile["Personal Smartphone Camera"]
Mobile -->|Opens Browser| Landing["Mobile Phishing Landing Page"]
Landing -->|Enters Mock Credentials| Teachable["Mobile Teachable Moment (Oops Page)"]
Teachable -->|Instant Coaching| LMS["Auto-Enrolled in Mobile Micro-Course"]
4. Key Business Benefits & Measurable ROI¶
- Bypasses Security Blindspots: Trains staff on the #1 vector currently circumventing Microsoft Defender and Google Workspace filters.
- Protects Both Corporate & BYOD Fleets: Instills security instincts that protect both company-managed phones and employee personal devices (BYOD).
- Granular Cross-Device Analytics: Isolates desktop views from mobile QR scans, giving CISOs clear visibility into multi-device human risk.
5. Real-World Attack Scenario & Case Study¶
- The Incident: Threat actors send an email impersonating IT Support titled "Action Required: Multi-Factor Authentication Migration to Authenticator v2". The email contains an embedded QR code with official Microsoft branding.
- The Vulnerability: 28% of untrained employees instinctively pull out their personal phones, scan the code, and enter their corporate credentials on the malicious mobile page.
- The QuishFire Defense: After two quarterly QuishFire simulation drills, employee scan rates drop to under 2.1%, and over 75% of employees report the email using the SimuPhish Outlook Add-in.
6. Competitive Edge: Why QuishFire Wins¶
| Capability | QuishFire | Competitor Offerings |
|---|---|---|
| Dynamic Vector Injection | Per-Recipient Crypto QR Tokens: Each recipient gets a unique QR code. | Static image shared across entire blast. |
| Cross-Device Telemetry | Desktop Open vs. Phone Scan: Explicitly separates device interactions. | Conflates mobile clicks with desktop clicks. |
| Mobile-Optimized Teachable Moments | Responsive Mobile UI: Instant coaching rendered natively on mobile screens. | Unresponsive desktop layouts shown on mobile. |
7. Target Buyer & Compliance Mapping¶
- Target Audience: CISO, VP of Information Security, Mobile Device Management (MDM) Leads.
- Regulatory Relevance:
- NIST SP 800-63B: Authenticator management and out-of-band verification.
- ISO 27001:2022 Control 5.14: Threat-driven security awareness.