Skip to content
Chitranjan Gupta edited this page Sep 29, 2022 · 12 revisions

Welcome to the QRPhishing wiki!

The Google Message Android Application is installed on most Android Smartphones.This application comprises a feature that enables us to access our messages on the web or the computer by scanning the QR Code. (https://messages.google.com/web)

But the hacker is exploiting this feature to get the OTP (One Time Password) from the user.

For Example

The hacker opens the Google Message web version on his system and scans his QR code from the victim's smartphone. He will be able to receive the OTP of the victim's smartphone on his system.

Now the question arises of how the hacker will scan his QR code from the victim's smartphone.

Here comes the answer.

Either the hacker somehow manages to get hold of the victim's smartphone and scan the QR code or makes the victim scan the QR code by offering free things like 'Scan this QR code to get an Amazon Voucher'.

Consequences of the attack

Now the hacker will send the Password Reset OTP of many services (Ex. Facebook, Whatsapp, etc.) on the victim number and the hacker receives it on his system. If the hacker has the ATM Card of the victim he can withdraw the money.