Threat Actors are Using Image-Based Phishing Emails to Lure Victims

Stu Sjouwerman | Jul 6, 2023

Image Based PhishingAttackers are increasingly using images in phishing to evade text-based security filters, according to researchers at INKY.

“Secure Email Gateways (SEGs) and similar security systems are designed to detect basic textual clues that signal phishing,” the researchers write. “One way around that is to design an email without text. In this case, the examples…actually contain no text. That’s right, no text. Instead, the text is embedded in an image and attached to the phishing email. This works because most email clients automatically display the image file directly to the recipient rather than delivering a blank email with an image attached. As a result, recipients don’t know that they are looking at a screenshot of text instead of HTML code with text and since there are no links or attachments to open, the email feels safe.”

The researchers observed a phishing campaign that used QR codes instead of text-based links.

“INKY decoded a malicious QR code to see where it was taking recipients,” the researchers write. “As predicted, victims scanning the QR code are unknowingly taken to a phishing site so that their credentials can be stolen. They’re quickly made to feel comfortable because malicious links embedded in QR codes contain the recipient’s email address as a URL parameter to prefill personal data once the phishing site loads. In short, things feel familiar.”

INKY offers the following recommendations to help users avoid falling for these attacks:

  • “Recipients should use a different means of communication to confirm whenever they are requested to complete a new task.
  • “Carefully inspect the sender’s email address. In these cases, emails claim to come from Microsoft and the recipient’s employer but the sender’s domain has no relation to these entities.
  • “Don’t scan QR codes from unknown sources. Websites reached by QR codes might host malicious code that exploits vulnerabilities or steals sensitive data.
  • “Be cautious when entering financial and personal information on a site reached with a QR code.”

New-school security awareness training can help your employees stay ahead of new social engineering tactics.

INKY has the story.

Topics: Phishing

Is Your Organization Vulnerable to Quishing?

Traditional filters often miss malicious links hidden in QR codes. Launch our Free Quishing Test for up to 100 users to identify security gaps and receive your custom Phish-prone Percentage report within 24 hours.

Get Your Free Quishing Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.