Quishing
Phishing delivered as a QR code, so the malicious address never appears as text anywhere a filter can read it. The code sits in an email attachment, a poster, a parking meter sticker or an invoice, and the victim resolves it with a device the organisation may not control.
Why it matters to you
The point of the technique is that it moves the click onto a phone. Mail security never sees a URL, the endpoint agent is not installed, and the browser showing the address bar is four inches wide. Treat any authentication that begins on an unmanaged device as a separate risk rather than as the same login from a different screen.
Where we meet it
Kits advertise the image rather than the page, because the image is the part that has to survive a mail gateway. Generators that produce a fresh code per recipient are sold as a feature, which is also what makes a single reported code useless as an indicator.
Connected terms
Lookalike domain
A domain registered to be misread as someone else's: a swapped character, an extra hyphen, a different suffix. The cheapest piece of infrastructure in this economy and the one most often pointed at a brand.
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Read elsewhere
Where this term stops being vocabulary
Dragnet is where you watch it happen to you
Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.