A new phishing campaign targeting German e-banking users has been launched in the past two weeks, which includes QR codes in the credential-snatching process.
See also: Phishing attacks target US universities

Hackers use a number of tricks to bypass security solutions and convince their targets to open the messages and follow the instructions.
The report comes from researchers at Cofense, who sampled several of these messages and mapped out the hackers' tactics in detail.
Phishing emails are carefully crafted, with bank logos, well-structured content, and a generally coherent style.
Their topics vary, from asking the user to consent to changes in the data policy implemented by the bank or asking the user to review new security procedures.
This approach is a sign of careful design, where threat actors do not make the typical exaggerated claims of account compromise and do not present the user with an emergency situation.
See also: Microsoft and Google OAuth flaws are being abused in phishing attacks
If the embedded button is clicked, the victim reaches the phishing site after going through Google's "FeedBurner" feed proxy service.
Additionally, hackers register their own custom domains that are used for these redirects as well as for the phishing sites themselves.
This additional step aims to trick email and internet security solutions so that any flags are not raised during the phishing process.
The domains are newly registered websites in the REG.RU registry in Russia and follow a standard URL structure depending on the targeted bank.

In the most recent phishing campaigns, threat actors are using QR codes instead of buttons to take victims to phishing sites.
These emails do not contain URLs and instead are disguised through QR codes, making them difficult for security software to detect.
QR codes have increased effectiveness as they target mobile phone users, who are less likely to be protected by Internet.
Once the victim reaches the phishing website, they are asked to enter their bank location, password, username, and PIN.
If these details are entered on the phishing page, the user waits for validation and is then asked to re-enter their credentials because they are incorrect.
See also: Twitter: Verified accounts become phishing targets after blue badge removal
This repetition is a common quality tactic in phishing campaigns to eliminate typos when the user enters their credentials the first time.
No matter how legitimate an email may seem, you should avoid clicking on buttons, URLs, or even QR codes that will take you to an external website.
Whenever you are asked to enter your account credentials, always remember to first validate the domain you are on before you start typing.
Information source: bleepingcomputer.com
