How It Works and Types of Attacks
QR Code attacks can be managed in two ways
-
paper format
-
email template containing QR code
This offers more flexibility in how to distribute the attack.
The ability to conduct a QR code attack is available to companies that have purchased the "Phish Pro" add-on and activated the relevant licenses.
Note: The mentioned add-on can be activated only after purchasing the "Phish Pro" component for the specific Organization. No activation is allowed for testing or trial purposes. If needed, please contact our support in advance.
Paper QR Code
To enable the QR code attack, you need to activate the "Enable QR Code Attacks" toggle available in the "Company Management > Setup > Phishing" section.
Once the toggle is enabled, proceed with the customization of the QR code by associating the landing page you want to use.
To do this, you can select "Training Material," indicate the company of interest, and finally "Template."
Proceed by selecting "Only QR code type templates" in the menu that allows filtering templates by type.
The global template displayed must then be copied to the company where you want to use it.
To copy the template, simply click on the pencil icon in the actions column and select the "Actions" section. A dropdown menu at the bottom shows the subdomains of the companies where the template can be copied.
Once the template is copied, becoming a "company template," you can customize it
-
By modifying the text of the email that will be sent to the contact containing the QR code to be printed
-
By choosing which landing page to associate
At this point, you can click on the "Release Management > Remediation > QR Code Attack" section
NOTE: Although it is within the remediation panel, the QR Code campaign can be activated even without campaigns conducted in Cyber Guru Phishing.
Clicking "Start" opens a screen where you can view the template containing the QR code. This template is only functional for sending the QR code to the contact who will then print it.
In the "Dates" section, you can specify the duration of the campaign underlying the attack.
You will need to specify
-
the start date of the attack's validity (from when user interactions with the QR code will be recorded)
-
the duration of the campaign (how long the system should record user interactions with the QR code). ANY EVENT AFTER THE SET DURATION WILL NOT BE RECORDED ON THE PLATFORM.
-
The start time of the campaign
-
In the "Email Sending Duration" field, you need to leave the default value PT2M, which indicates that the email to the contact will be sent within 2 minutes.
In the "Target" section, you can enter the name, surname, email, and language of the user (contact) who will receive the QR code via email.
The QR code can also be sent simultaneously to multiple contacts.
In this section, do NOT specify the campaign targets, as you are defining a QR code attack without predetermined targets (anyone could scan the QR code).
Once the information is entered, the supervisor receives a QR Code that can be printed and physically distributed.
Tracking Interaction with QR Code
When a user scans the QR Code, they are redirected to a phishing link.
There are two levels of tracking available:
-
Level 1: Anonymous tracking of the number of people who followed the link after scanning the QR Code.
-
Level 2: If the user enters information (e.g., username and password), the tracking becomes more detailed and can be configured to capture specific data fields. This second scenario can occur by inserting an intermediate landing page after scanning the QR Code
Note: Entered passwords are not saved unless the password capture option is explicitly enabled within the landing page.
Once the remediation is complete, the data will be viewable in the "Statistics > Remediation Report" section
Within the reporting, you can view
-
The IP from which the click originated
-
Any information entered in the intermediate landing
QR Code via Email
A more advanced option that allows for greater traceability is sending QR Codes via email.
In this case, the tracking is no longer anonymous but detailed, like any regular phishing email campaign.
It is recommended to use the QR Code via email as it offers complete tracking and greater accuracy in results.
If you want to conduct a campaign with a template containing a QR code, you will need to copy the template to the company of interest (leaving the global template inactive) and customize it as indicated above.