Chinese citizens have been targeted by a phishing campaign, which uses QR codes (quishing) on fake “official” documents to deceive victims.

According to new research from Cyble Research and Intelligence Labs (CRIL), attackers are using Microsoft Word files that look like official documents from the Chinese Ministry of Human Resources and Social Security. Security researchers believe the files are being distributed via phishing emails.
The document used in this quishing campaign is presented as a notice for applying for subsidies labor. It claims to offer subsidies of over 1,000 yuan ($138) for registered bank cards. It then directs users to use their mobile phones to scan a QR code for authentication in order to receive the subsidy.
See also: New phishing toolkit uses PWA to steal login credentials
Theft of financial information
When the user scans the QR code in the Word, they are directed to a URL with the subdomain “tiozl[.]cn,” which is generated using a Domain Generation Algorithm (DGA). This URL hosts a phishing website impersonating the Ministry of Human Resources and Social Security of China.
When the user proceeds to claim the subsidy, they are redirected to another page. There, they are asked to enter personal information, including their name and national ID.
According to Cyble researchers, the goal of this quishing campaign is to collect financial information (credit card details and passwords )in order to make unauthorized transactions.
See also: Phishing emails promote malicious scripts via Windows search protocol
Quishing: Increase in phishing attacks with QR codes
Quishing attacks have become increasingly popular in recent years.
In fact, a new phishing-as-a-service (PhaaS) platform called ONNX Store uses QR codes in PDF attachments and targets Microsoft 365 accounts of financial services employees. In these attacks, scanning the QR code on a mobile device bypasses phishing protections at the targeted organizations, leading victims to phishing pages that mimic the legitimate Microsoft 365 login interface.
At that point, the victim is prompted to enter their login credentials and 2FA token on the fake login page. The data is recorded on the phishing site and transmitted to the attackers in real time. This allows them to compromise the account before the authentication expires.
According to Cyble, there are several reasons for the increase in quishing attacks:
- The recent widespread adoption of QR codes
- The integration of QR code scanners into smartphones
- The rise of mobile payment systems
- The very nature of QR codes, since they do not reveal to the user the URL to which they redirect
See also: Phishing attacks: Significant increase in the US and Europe

Protection
Cyble provided a list of recommendations for mitigating the threat:
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Scan QR codes only from trusted sources
Avoid scanning codes from unsolicited emails, messages, or documents.
After scanning a QR code, check the URL carefully.
Look for signs of legitimacy, such as official domains and secure connections (https://).
Install reliable antivirus and anti-phishing
Antivirus software can help identify and block malicious websites and downloads.
Use two-factor authentication (2FA))
Secure all your online accounts with 2FA to prevent access even when credentials have been compromised.
Apply the latest security updates
Keep your operating systems, browsers, and applications up to date. This helps protect against known vulnerabilities.
Check your bank account transactions
Regularly check your account and credit card for possible unauthorized transactions. Report any suspicious activity to your bank immediately.
Source: www.infosecurity-magazine.com
