Skip to content

QuishFire: QR Code Phishing (Quishing) Simulation

Platform Feature: QuishFire
UI Location: Main Navigation > Attack Vector Arsenal > QuishFire (/quishfire)
Threat Forge Scenarios: Threat Forge > QR Scenarios (/qr-scenarios)
Telemetry & Reports: Posture Reports > QuishFire Simulation Reports


1. Executive Summary & Value Proposition

Quishing (QR Code Phishing) is one of the fastest-growing social engineering tactics worldwide. Attackers embed malicious URLs inside Quick Response (QR) codes, completely bypassing Secure Email Gateways (SEGs) and transferring the victim from a protected corporate desktop to an unmanaged personal smartphone.

QuishFire, SimuPhish’s specialized QR code phishing simulation module, trains employees to recognize QR deception, measures cross-device vulnerability, and inoculates organizations against mobile credential harvesting.


2. The Threat Landscape & The Real-World Problem Solved

  • The Problem: Traditional Secure Email Gateways inspect plain text, HTML links, and file attachments. When an attacker sends an email containing an embedded QR code, traditional mail filters see only a harmless image.
  • The Device Shift Attack: By scanning the QR code with their mobile phone, the employee moves the transaction off the corporate network and corporate-monitored workstation onto their personal device, where endpoint detection (EDR), browser protection, and corporate DNS filtering are completely absent.
  • Explosive Growth: Security research reports show that QR code phishing incidents increased by over 580% year-over-year, targeting corporate 2FA registrations, parking passes, open enrollment, and cafeteria menus.

3. How It Works (The User Journey)

The Administrator Experience

  1. Campaign Configuration: Navigate to Attack Vector Arsenal > QuishFire (/quishfire) and select target groups from active directories or specific departments (e.g., Sales, HR, Executives).
  2. AI-Assisted QR Pretext Generation: Choose from dynamic templates under Threat Forge > QR Scenarios (e.g., "Mandatory Authenticator App Migration", "Annual Compensation Review", "Office Wi-Fi Re-Authentication") or generate new pretext lures using AI.
  3. Dynamic QR Encoding: QuishFire automatically generates unique, high-resolution QR codes embedded with cryptographic tracking tokens per recipient.
  4. Cross-Device Tracking: Administrators receive distinct analytics showing:
  5. How many employees opened the email on desktop.
  6. How many employees took out their smartphones and scanned the QR code.
  7. How many entered mock credentials on the mobile landing page.

The Employee Experience

  1. The employee opens an email instructing them to scan a QR code using their mobile phone camera.
  2. When scanned, the phone’s browser opens a mobile-optimized mock login page.
  3. If mock credentials are submitted, the employee is immediately presented with a mobile-friendly Teachable Moment (Oops Page) explaining:
  4. Why corporate services will never ask you to scan a QR code to verify login credentials.
  5. How to spot illegitimate QR codes on screens, posters, and emails.
graph LR
    Desktop["Employee views email on Corporate PC"] -->|Scans QR Code with Phone| Mobile["Personal Smartphone Camera"]
    Mobile -->|Opens Browser| Landing["Mobile Phishing Landing Page"]
    Landing -->|Enters Mock Credentials| Teachable["Mobile Teachable Moment (Oops Page)"]
    Teachable -->|Instant Coaching| LMS["Auto-Enrolled in Mobile Micro-Course"]

4. Key Business Benefits & Measurable ROI

  • Bypasses Security Blindspots: Trains staff on the #1 vector currently circumventing Microsoft Defender and Google Workspace filters.
  • Protects Both Corporate & BYOD Fleets: Instills security instincts that protect both company-managed phones and employee personal devices (BYOD).
  • Granular Cross-Device Analytics: Isolates desktop views from mobile QR scans, giving CISOs clear visibility into multi-device human risk.

5. Real-World Attack Scenario & Case Study

  • The Incident: Threat actors send an email impersonating IT Support titled "Action Required: Multi-Factor Authentication Migration to Authenticator v2". The email contains an embedded QR code with official Microsoft branding.
  • The Vulnerability: 28% of untrained employees instinctively pull out their personal phones, scan the code, and enter their corporate credentials on the malicious mobile page.
  • The QuishFire Defense: After two quarterly QuishFire simulation drills, employee scan rates drop to under 2.1%, and over 75% of employees report the email using the SimuPhish Outlook Add-in.

6. Competitive Edge: Why QuishFire Wins

Capability QuishFire Competitor Offerings
Dynamic Vector Injection Per-Recipient Crypto QR Tokens: Each recipient gets a unique QR code. Static image shared across entire blast.
Cross-Device Telemetry Desktop Open vs. Phone Scan: Explicitly separates device interactions. Conflates mobile clicks with desktop clicks.
Mobile-Optimized Teachable Moments Responsive Mobile UI: Instant coaching rendered natively on mobile screens. Unresponsive desktop layouts shown on mobile.

7. Target Buyer & Compliance Mapping

  • Target Audience: CISO, VP of Information Security, Mobile Device Management (MDM) Leads.
  • Regulatory Relevance:
  • NIST SP 800-63B: Authenticator management and out-of-band verification.
  • ISO 27001:2022 Control 5.14: Threat-driven security awareness.