newsbucuresti.ro QR Code Phishing Attacks Target Authentication Data and Crypto Wallets
Article Content
- •10% of email phishing threats bypass security filters.
- •QR codes are used to redirect victims to phishing sites.
- •Malware targets cryptocurrency wallet extensions to steal data.
Phishing attacks using QR codes are increasingly prevalent, with at least 10% of email threats bypassing security filters, according to the HP Threat Insights Report. Attackers send PDF documents with blurred content, prompting victims to scan QR codes that redirect them to phishing sites. Additionally, cybercriminals exploit interest in AI by promoting fake trading agents that install malware on devices. This malware scans for cryptocurrency wallet extensions, replacing them with malicious versions to steal authentication data. The report also highlights the expansion of the Phantom Stealer ecosystem, with the identification of a new malware loader named Phantom Gate. Executable files remain the primary method for delivering malware, accounting for 40% of cases. Users are advised to avoid scanning unsolicited QR codes and to verify website authenticity before entering sensitive information.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Phantom Gate and Coinbase in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cybercriminals Use Fake AI Agents to Steal Crypto Wallets Cybercriminals are exploiting interest in Agentic AI by creating fake AI trading agents to lure crypto users into downloading malware. This malware, known as Needle Stealer, replaces legitimate browser wallet extensions like MetaMask and Coinbase with malicious versions that capture user credentials. The attacks were…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…