HPQ HP Inc.

Daily QR “Scan Scams” Phishing Users on their Mobile Devices

Daily QR “Scan Scams” Phishing Users on their Mobile Devices

New HP Wolf Security report shows move to block macros by default is forcing threat actors to think outside the ‘box’

PALO ALTO, Calif., March 16, 2023 (GLOBE NEWSWIRE) -- HP Inc. (NYSE: HPQ) today issued its latest quarterly , showing hackers are diversifying attack methods, including a surge in QR code phishing campaigns. By isolating threats on PCs that have evaded detection tools, HP Wolf Security has insights into the latest techniques being used by cybercriminals in the fast-changing cybercrime landscape. To date, HP Wolf Security customers have clicked on over 25 billion email attachments, web pages, and downloaded files with no reported breaches. Further HP Wolf Security insights will be featured at the upcoming Amplify Partner Conference, March 28-30, McCormick Place Chicago.

From February 2022, Microsoft began blocking macros in , making it harder for attackers to run malicious code. Data collected by the HP Threat Research team shows that from Q2 2022, attackers have been diversifying their techniques to find new ways to breach devices and steal data. Based on data from millions of endpoints running HP Wolf Security1, the research found:

  • The rise of QR scan scams: Since October 2022, HP has seen almost daily QR code “scan scam” campaigns. These scams trick users into scanning QR codes from their PCs using their mobile devices – potentially to take advantage of weaker phishing protection and detection on such devices. QR codes direct users to malicious websites asking for credit and debit card details. Examples in Q4 included phishing campaigns masquerading as parcel delivery companies seeking payment.
  • HP noted a 38% rise2 in malicious PDF attachments: Recent attacks use embedded images that link to encrypted malicious ZIP files, bypassing web gateway scanners. The PDF instructions contain a password that the user is tricked into entering to unpack a ZIP file, deploying QakBot or IcedID malware to gain unauthorized access to systems, which are used as beachheads to deploy ransomware.
  • 42% of malware was delivered inside archive files like ZIP, RAR, and IMG: The popularity of archives has risen 20% since Q1 2022, as threat actors switch to scripts to run their payloads. This is compared to 38% of malware delivered through Office files such as Microsoft Word, Excel, and PowerPoint.

“We have seen malware distributors like Emotet try to work around Office’s stricter macro policy with complex social engineering tactics, which we believe are proving less effective. But when one door closes another opens – as shown by the rise in scan scams, malvertising, archives, and PDF malware,” explains Alex Holland, Senior Malware Analyst, HP Wolf Security threat research team, HP Inc.

“Users should look out for emails and websites that ask to scan QR codes and give up sensitive data, and PDF files linking to password-protected archives.”

In Q4, HP also found 24 imitated in malvertising campaigns used to infect PCs with eight malware families – compared to just two similar campaigns in the previous year. The attacks rely on users clicking on search engine advertisements, which lead to malicious websites that look almost identical to the real websites.

“While techniques evolve, threat actors still rely on social engineering to target users at the endpoint,” comments Dr. Ian Pratt, Global Head of Security for Personal Systems, HP Inc.

“Organizations should deploy strong isolation to contain the most common attack vectors like email, web browsing and downloads. Combine this with credential protection solutions that warn or prevent users from entering sensitive details onto suspicious sites to greatly reduce the attack surface and improve an organization’s security posture.”

HP Wolf Security runs risky tasks like opening email attachments, downloading files and clicking links in isolated, micro-virtual machines (micro-VMs) to protect users, capturing detailed traces of attempted infections. HP’s application isolation technology mitigates threats and provides unique insights into novel intrusion techniques and threat actor behavior.

The full report can be found here:

About the data

This data was anonymously gathered within HP Wolf Security customer virtual machines from October-December 2022.

About HP

HP Inc. (NYSE: HPQ) is a global technology leader and creator of solutions that enable people to bring their ideas to life and connect to the things that matter most. Operating in more than 170 countries, HP delivers a wide range of innovative and sustainable devices, services and subscriptions for personal computing, printing, 3D printing, hybrid work, gaming, and more. For more information, please visit: .

About HP Wolf Security

HP Wolf Security is a new breed of endpoint security. HP’s portfolio of hardware-enforced security and endpoint-focused security services are designed to help organizations safeguard PCs, printers, and people from circling cyber predators. HP Wolf Security provides comprehensive endpoint protection and resiliency that starts at the hardware level and extends across software and services. Visit .


1 HP Security is now HP Wolf Security. Security features vary by platform, please see product data sheet for details.

2 As detailed in page 2 of the HP Wolf Security Q4 Threat Insights Report

Media Contacts

Vanessa Godsal

HP Media Relations



EN
16/03/2023

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on HP Inc.

 PRESS RELEASE

Updated time: HP Inc. to Announce Third Quarter Fiscal 2025 Earnings o...

Updated time: HP Inc. to Announce Third Quarter Fiscal 2025 Earnings on Aug 27, 2025 PALO ALTO, Calif., Aug. 14, 2025 (GLOBE NEWSWIRE) -- HP Inc. (NYSE: HPQ) will present a live audio webcast of a conference call to review financial results for the third fiscal quarter ended July 31, 2025 on Wednesday, Aug 27, 2025 at 4:30 p.m. ET / 1:30 p.m. PT. The webcast will be available at . A replay of the audio webcast will be available at the same website shortly after the call and will remain available for approximately one year. About HP Inc. HP Inc. (NYSE: HPQ) is a global ...

 PRESS RELEASE

HP Cranks Up the Game with Smarter Systems, Cooler Builds, and Gear Th...

HP Cranks Up the Game with Smarter Systems, Cooler Builds, and Gear That Hits Different From pro-level performance to creator-grade sound, the newest OMEN and HyperX lineup gives gamers more ways to play harder, stream better, and stay in control News Highlights: Delivers extreme performance with OMEN MAX 45L, HP’s most powerful gaming desktop with the industry’s first patented CRYO CHAMBER™ cooling,1 offering a 7.5°C drop in CPU temperatures under full load compared to mid-size or dual chamber modelsEnhances performance with OMEN AI, the world’s first AI-driven, one-click performance...

 PRESS RELEASE

HP Inc. to Announce Third Quarter Fiscal 2025 Earnings on Aug 27, 2025

HP Inc. to Announce Third Quarter Fiscal 2025 Earnings on Aug 27, 2025 PALO ALTO, Calif., Aug. 05, 2025 (GLOBE NEWSWIRE) -- HP Inc. (NYSE: HPQ) will present a live audio webcast of a conference call to review financial results for the third fiscal quarter ended July 31, 2025 on Wednesday, Aug 27, 2025 at 5:00 p.m. ET / 2:00 p.m. PT. The webcast will be available at . A replay of the audio webcast will be available at the same website shortly after the call and will remain available for approximately one year. About HP Inc.HP Inc. (NYSE: HPQ) is a global technology leader and crea...

 PRESS RELEASE

HP Inc. Declares Dividend

HP Inc. Declares Dividend PALO ALTO, Calif., June 10, 2025 (GLOBE NEWSWIRE) -- HP Inc. (NYSE: HPQ) has declared a cash dividend of $0.2894 per share on the company’s common stock. The dividend, the fourth in HP’s fiscal year 2025, is payable on October 1, 2025, to stockholders of record as of the close of business on September 10, 2025. HP has approximately 0.9 billion shares of common stock outstanding. About HP Inc. HP Inc. (NYSE: HPQ) is a global technology leader and creator of solutions that enable people to bring their ideas to life and connect to the things that matter mo...

 PRESS RELEASE

HP Inc. Reports Fiscal 2025 Second Quarter Results

HP Inc. Reports Fiscal 2025 Second Quarter Results PALO ALTO, Calif., May 28, 2025 (GLOBE NEWSWIRE) -- HP (NYSE: HPQ) Second quarter GAAP diluted net earnings per share ("EPS") of $0.42, down 31% from the prior year periodSecond quarter non-GAAP diluted net EPS of $0.71, down 13% from the prior year periodSecond quarter net revenue of $13.2 billion, up 3.3% from the prior-year periodSecond quarter net cash provided by operating activities of $38 million, free cash flow of $(95) millionSecond quarter returned $0.4 billion to shareholders in the form of dividend and share repurchases HP...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch