{"id":19494,"date":"2022-07-01T05:30:03","date_gmt":"2022-07-01T13:30:03","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/07\/01\/news-13227\/"},"modified":"2022-07-01T05:30:03","modified_gmt":"2022-07-01T13:30:03","slug":"news-13227","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/07\/01\/news-13227\/","title":{"rendered":"Scammers used phishing QR codes to hijack QQ accounts | Kaspersky official blog"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/07\/01091807\/phishing-qr-code-attack-on-qq-users-featured.jpg\"\/><\/p>\n<p><strong>Credit to Author: Anastasia Starikova| Date: Fri, 01 Jul 2022 13:19:12 +0000<\/strong><\/p>\n<p>Folks today are generally mostly aware that clicking links from questionable sources, for example in e-mails, isn&#8217;t a good idea. However, when it comes to scanning QR codes, people are often much less vigilant. In fact, QR codes can be even more dangerous: while you can check a link with your own eyes before clicking, that&#8217;s not the case with a QR code. So perhaps this story about a phishing QR-code attack in China shouldn&#8217;t come as a surprise.<\/p>\n<h2>What happened?<\/h2>\n<p>The other day it was <a href=\"https:\/\/www.theregister.com\/2022\/06\/28\/tencent_qq_qr_code_attack\/\" target=\"_blank\" rel=\"nofollow noopener\">reported<\/a> that unknown cybercriminals distributed phishing QR codes offering free game logins, which they then used to hijack some accounts of the QQ messaging and social media platform.<\/p>\n<p>While largely unknown outside China, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Tencent_QQ\" target=\"_blank\" rel=\"nofollow noopener\">QQ<\/a> is a HUGE deal there, with hundreds of millions active users. The platform provides all kinds of services, including chatting, watching movies, blogging, and gaming \u2014 the latter service being the relevant one in this case. It&#8217;s developed by Chinese tech giant Tencent.<\/p>\n<p>Due to the regional specific, it&#8217;s difficult to tell how exactly the attack began or how many accounts were stolen. However, the incident was large enough for Tencent to publicly apologize in a post on Sina Weibo \u2014 the Chinese version of Twitter.<\/p>\n<p>The mechanics of the attack are more or less clear. As mentioned above, attackers spread malicious QR codes offering free game logins. After scanning such QR codes, users were asked to authenticate with their QQ account. Once they did, the attackers stole the victims&#8217; credentials to then use them for their own gain. As a result, an unknown number of people were locked out of their QQ accounts.<\/p>\n<p>Tencent is aware of the issue and has since restored the affected accounts. The company is working with the local authorities to find out more about the attack.<\/p>\n<h2>Protect yourself<\/h2>\n<p>Although this case mainly affected greater China, the threat of malicious QR codes should not be underestimated \u2014 especially since QR codes have become so ubiquitous in recent years mainly thanks to covid. To be on the safe side, when scanning QR codes, use our Kaspersky QR Scanner (available for both <a href=\"https:\/\/app.appsflyer.com\/com.kaspersky.qrscanner?pid=smm&#038;c=ww_kdailyplaceholder\" target=\"_blank\">Android<\/a> and <a href=\"https:\/\/app.appsflyer.com\/id948297363?pid=smm&#038;c=ww_kdailyplaceholder\" target=\"_blank\">iOS<\/a>). The app will tell you if the code points to a dangerous site.<\/p>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"ksc-trial-generic\" \/> <br \/><a href=\"https:\/\/www.kaspersky.com\/blog\/phishing-qr-code-attack-on-qq-users\/44767\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2022\/07\/01091807\/phishing-qr-code-attack-on-qq-users-featured.jpg\"\/><\/p>\n<p><strong>Credit to Author: Anastasia Starikova| Date: Fri, 01 Jul 2022 13:19:12 +0000<\/strong><\/p>\n<p>How scammers hijacked QQ accounts in a phishing QR-code attack.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[11059,1445,3924,18765,10438],"class_list":["post-19494","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-games","tag-gaming","tag-phishing","tag-qr-codes","tag-threats"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19494","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19494"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19494\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19494"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}