Get a free trial →

Push Logo

Mobile phishing: how to detect and stop QR code (quishing) and SMS (smishing) phishing

Geometry graphic

QR code and SMS phishing bypass email security entirely

How mobile phishing attacks like quishing and smishing work

  1. The attacker sends a phishing link via SMS, messaging apps, or embeds it in a QR code
  2. The user scans or taps the link on their mobile device
  3. The link opens in a browser, often outside corporate protections
  4. The user interacts with a phishing page, entering credentials or approving access
  5. The attacker captures credentials, sessions, or tokens and gains access

Why email security misses QR code and SMS phishing

Diagram illustrating why traditional email security and endpoint tools miss mobile phishing attacks delivered via QR codes and SMS links.

How Push detects phishing regardless of delivery channel

Push Security blocking a fake login page opened from a QR code phishing link on a mobile browser, detecting credential harvesting in real time.

Frequently asked questions

QR code phishing uses QR codes to deliver phishing links — typically embedded in emails, documents, or physical media. When the user scans the code, they're directed to a phishing page. The technique bypasses email security because the phishing URL is encoded inside an image that text-based scanners can't reliably parse.

QR codes are inherently opaque — the user can't see the destination URL before scanning. The phishing page loads on the user's phone, which may lack corporate security controls. Push detects the phishing destination regardless of how the user arrived at it.

Detection at the phishing page itself, because QR codes bypass the email delivery channel where most phishing controls operate. If the user opens the link in a Push-protected browser, the phishing page is detected by the same behavioral analysis that catches email-delivered phishing.

The channel-agnostic nature of browser-based detection is critical for QR code attacks — the entire purpose of QR code delivery is to evade email-centric controls.

A tool that detects phishing at the destination page level rather than the delivery channel. QR codes, SMS, and social media all bypass email security.

Push provides channel-agnostic detection — whether a phishing link arrives via QR code, SMS, WhatsApp, LinkedIn DM, or search ad, Push detects the phishing page when the user opens it in a protected browser.

Most email security tools struggle with it. The phishing URL is encoded inside an image, and many gateways don't reliably decode QR codes embedded in email bodies, attached PDFs, or images. Attackers use techniques like splitting QR codes across multiple images, using Unicode characters, and embedding them in PDF attachments.

Email security is also structurally limited to the email channel — it can't detect QR codes delivered via physical printouts, messaging apps, or social media. Push provides the backstop by detecting the phishing page when it loads in the browser.

SMS phishing bypasses email security entirely and arrives on mobile devices that may lack corporate security controls. The most effective defense is behavioral phishing detection in the browser — catching the phishing page regardless of whether the user clicked a link in a text message, email, or anywhere else.

Push detects phishing destinations regardless of delivery channel. If the SMS link opens in a Push-protected browser, the phishing page is detected behaviorally.

QR codes encode URLs as images. Email gateways scan text-based content — URLs, headers, and attachments. Even gateways with QR code scanning face evasion: QR codes split across multiple images, embedded in PDFs, constructed from Unicode text, or generated as SVG images.

The fundamental limitation is structural. Email gateways operate at the delivery channel, and QR codes exist specifically to bridge to a different channel. Push operates at the destination — detecting the phishing page when it renders.

Their device opens a URL — typically a phishing page designed to steal credentials, session tokens, or OAuth consent. The destination may be an AiTM reverse proxy, a cloned login page, or an OAuth consent page. The user experience feels normal: scan the code, see a login page, enter credentials. The attack is over in seconds.

If Push is deployed, it detects the phishing page behaviorally when it loads — regardless of whether the URL has been reported before.

Yes. Push detects phishing at the browser level — analyzing the destination page, not the delivery channel. Whether the link arrives via email, SMS, QR code, social media, search ads, messaging apps, or physical media, Push detects the phishing page when it loads in a protected browser.

Push's behavioral detection targets the phishing technique (AiTM kit behavior, cloned login pages, credential harvesting) rather than the delivery mechanism.

QR codes encode the phishing URL as an image rather than a clickable text link. Email gateways that scan URLs and rewrite them for time-of-click analysis can't parse URLs embedded in QR code images.

Evasion techniques include embedding QR codes in PDF attachments, splitting them across multiple images, generating them as SVGs, and constructing them from Unicode characters. Some campaigns add multiple URL shortener redirects before the phishing destination.

Phishing is the broad category — social engineering to steal credentials, authorization, or execution. Smishing is phishing via SMS. Quishing is phishing via QR codes. The technique at the destination is often identical (AiTM proxy, cloned login page, credential harvesting); only the delivery channel differs.

The distinction matters for defense because most security investments focus on email. Push's channel-agnostic detection addresses all three — detecting the phishing page regardless of delivery method.