DETECTION AND CONTAINMENT OF QR CODE ATTACKS (MEDUSA; QRISHING/QUISHING) USING MALWARE IN MOBILE APPLICATIONS IN MEXICO
DETECTION AND CONTAINMENT OF QR CODE ATTACKS (MEDUSA; QRISHING/QUISHING) USING MALWARE IN MOBILE APPLICATIONS IN MEXICO
-
DOI: https://doi.org/10.22533/at.ed.317512507012
-
Palavras-chave: QR, Malware, QRhising, Ataque Medusa, Aplicativo Móvel
-
Keywords: QR, Malware, QRhising, Medusa Attack, Mobil App
-
Abstract: The use of QR codes (Quick Response) in all areas of technology worldwide is booming, due to their ease of reading and access to computer resources or financial assets, this has repercussions on deception and fraud. to the users and companies that trust them. In theory and practice the codes are safe, but excessive use can lead to deception and threats that cause the theft of personal data and financial fraud. “Qrishing” frauds (a technique that aims to deceive victims by impersonating web pages) are growing at an alarming rate, generating million-dollar losses. This type of fraud, which redirects users to malicious sites by simply scanning a code, or which can also download and install malware on the devices that read it, generates million-dollar losses for companies, governments, and users. This research work proposes an alternative solution to the validation, verification, and detection of malicious software in QR codes, by characterizing the most common attacks (such as the Medusa attack; QRishing/Quishing), based on the consultation and analysis of a mobile application that helps detect malware (malicious software) or links from fraudulent sites, in order to warn and prevent the user from using them.
- Heberto Ferreira Medina
- Juan Jesús Ruiz-Lagunas
- Anastacio Antolino Hernández
- Miguel Espejel Cruz
- J. Guadalupe Ramos Díaz