How it works and types of attacks
PhishPro offers two different QR Code attacks, each with its own setup:
- Printed QR Code: The QR Code is printed and physically distributed by the designated contact.
- QR Code via email: The QR Code is included in an email template used in phishing campaigns.
The QR Code attack is available for companies that have purchased the "Phish Pro" Add-on and activated the corresponding licenses.
Note: The Add-on can be activated only after purchasing the "Phish Pro" component for the specific Organization. No activation is allowed for testing or trial purposes. If needed, please contact our support team in advance.
Printed QR Code
Activation
To enable the attack, turn on the "Enable QR code Attacks" toggle in Company Management > Setup > Phishing.
The global printed QR Code template is already active and linked to a standard landing page, which is recommended and designed for this type of attack. If the standard landing page works for you, you can go straight to launching the campaign.
Template customization (optional)
Customization is only needed if you want users to land on a different page than the standard one. In this case, you need to copy the global template to your company (contact your CSM for support):
- Go to Training Material, select your company, and open Templates.
- In the type filter, choose "Only QR code templates".
- On the global template, click the pencil icon in the Actions column and open the Actions section.
- From the dropdown menu at the bottom, select the company subdomain where you want to copy the template.
To copy the template, just click the pencil icon in the actions column and select the "Actions" section. At the bottom, a dropdown menu will show the company subdomains where you can copy the template.
The copied template becomes a company template, which you can customize:
- by choosing the landing page to link to;
- by editing, if needed, the email text that the contact will receive with the QR Code to print.
Launching the campaign
If you want to proceed with the standard template, you can skip the previous steps and go straight to the following ones.
- Go to Release Management > Remediation > QR code Attack and click Start.
- Select the QR Code template to use: either the global one or your customized copy. The template is sent only to the specified contacts, who are responsible for printing and distributing the QR Code.
- Fill out the Dates section. You’ll need to specify:
- Campaign start date: the day from which user interactions with the QR code will be tracked on the platform.
-
Campaign duration: defines how long the system will track user interactions with the QR code.
⚠️ Any interaction after the set duration will not be recorded on the platform.
- Campaign start time: specify the exact time (on the chosen start date) when the campaign becomes active and user interactions with the QR code begin to be tracked on the platform.
-
Email sending duration: leave the default value PT2M. This field means that, within two minutes of the set start date, the contact will receive the QR code to print via email. For this reason, it’s important for the contact to print and distribute the QR code as soon as possible to avoid losing tracking days.
Alternatively, you can set a longer campaign duration to allow for any delays in printing and distributing the QR code.
- Fill out the Target section with the contact’s first name, last name, email, and language. The QR code can be sent to multiple contacts at once. Do NOT enter campaign targets in this section, as this is a QR code attack without predefined targets (anyone can scan the QR code).
NOTE: Even though it’s in the remediation panel, the QR Code campaign can be launched even if you haven’t run any campaigns in Cyber Guru Phishing.
Once all information is entered, the supervisor receives a QR Code that can be printed and distributed physically (the QR code will be sent within 2 minutes of the set start date)
Tracking QR code interactions
When a user scans the QR Code, they are redirected to a phishing link.
There are two levels of tracking available:
- Level 1: Anonymous tracking of the number of people who followed the link after scanning the QR Code.
-
Level 2: If the user enters information (e.g., username and password), tracking becomes more detailed and can be set up to capture specific data fields. This scenario can occur by adding an intermediate landing page after the QR Code is scanned.
Note: Passwords entered are not saved unless the password capture option is explicitly enabled on the landing page.
Once remediation is complete, the data will be available in the "Statistics > Remediation Report" section.
Within the reports, you can view:
The IP address from which the click originated
Any information entered on the intermediate landing page
QR Code via email (RECOMMENDED)
A more advanced option that allows for greater traceability is sending QR Codes via email.
In this case, tracking is no longer anonymous, but detailed, just like any regular phishing email campaign.
We recommend using QR Code via email because it offers full tracking and more accurate results.
QR Code templates are made available in two ways:
- Templates pushed by the CSM: The CSM pushes the QR Code templates, which are then available for use in phishing campaigns.
-
Copy of the global template: The CSM provides a copy of the global template in the company. The customer can customize it and use it independently in campaigns.