Case Library / Quishing (QR Code Phishing) / LevelBlue MTDR SOC "Quishing" Case Study - Fake Microsoft MFA-Setup QR Code Harvests Employee Credentials (2023)

LevelBlue MTDR SOC "Quishing" Case Study - Fake Microsoft MFA-Setup QR Code Harvests Employee Credentials (2023)

LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a malicious QR code, drove multiple employees to a fake Microsoft login page that harvested several employees' credentials before the attack was fully remediated with no confirmed data loss.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In a case documented by LevelBlue (formerly AT&T Cybersecurity) and published October 10, 2023, the LevelBlue Managed Detection and Response (MTDR) security operations center detailed a real client incident involving "quishing" (QR-code phishing). Multiple employees at an unnamed customer organization received a phishing email with a PDF attachment containing a QR code and an urgent message impersonating a Microsoft/Windows multi-factor-authentication (MFA) setup requirement. Employees who scanned the QR code with their phones were redirected to a fake Microsoft login page that harvested their usernames and passwords; several users' credentials were compromised. The customer flagged the email as suspicious and engaged LevelBlue analysts, who decoded the QR code's destination (srvc1[.]info/mcrsft2fasetup/index.html), analyzed the credential-harvesting page's network behavior using a decoy account and Chrome DevTools, and researched the attacker's infrastructure via OSINT. LevelBlue then guided the customer through remediation: closing active sessions before resetting credentials, purging the phishing email from inboxes, blocking the malicious domains, and confirming no data had been exfiltrated. No exact employee count, dollar figure, or victim organization name/sector was disclosed in the public write-up.

How the Attack Worked

Attackers sent a phishing email to multiple employees at the customer organization, styled as an urgent notification that Windows/Microsoft multi-factor authentication (MFA) needed to be set up on the recipient's account. Rather than a clickable link, the email carried a PDF attachment instructing the recipient to scan an embedded QR code to complete MFA enrollment. Because the malicious payload was an image (the QR code) rather than a URL or macro, it evaded traditional email-gateway link/attachment scanning. Employees who scanned the code with their phones (deliberately chosen by the attacker because mobile devices typically have weaker security controls than corporate-network endpoints) were redirected to a convincing fake Microsoft sign-in page and entered their real credentials, which were captured by the threat actor. LevelBlue MDR SOC analysts, engaged after the customer flagged the email as suspicious, decoded the QR code to the URL srvc1[.]info/mcrsft2fasetup/index.html, then used a decoy email address and Google Chrome's Inspector/DevTools network panel to observe what the credential-harvesting page did after "Sign In" was clicked, finding a single outbound call to logo.clearbit[.]com/email.com (an innocuous marketing-intelligence lookup, returning HTTP 404) rather than further malicious exfiltration traffic. OSINT on srvc1[.]info showed it was a recently registered, ownership-obscured domain with no other footprint, and the customer confirmed neither srvc1[.]info nor Clearbit were part of its normal business tooling.

The Lure & the Tell

Lure: an email posing as an official notice that the recipient's Microsoft/Windows multi-factor authentication needed to be set up, with a PDF attachment containing a QR code to "complete enrollment" and urgency language pressuring quick action. Tell (in hindsight): legitimate MFA enrollment is initiated by internal IT/identity systems, not via an unsolicited PDF with a QR code; the destination domain (srvc1[.]info/mcrsft2fasetup) had no relation to microsoft.com or the organization's actual identity provider; and the attacker's explicit bet, that victims would scan with a phone precisely to bypass corporate network security, was itself an exploitable "tell" once flagged (why would MFA setup require leaving the managed device?).

Outcome

Several employees' credentials were compromised, but LevelBlue's investigation found no evidence of successful data exfiltration and no indicators the phishing email had spread further inside the organization. Working with LevelBlue MDR SOC analysts, the customer closed all active sessions before resetting user credentials (to prevent the attacker retaining access through the reset), purged the phishing email from all inboxes, and blocked the external domains tied to the QR code (srvc1[.]info and the Clearbit lookup domain). The incident was declared fully remediated and the customer used it as a lessons-learned exercise to retrain staff on phishing and malicious-QR-code risks. No public confirmation of the victim organization's identity, sector, employee count, or any financial/breach-notification impact was released.

Why It Matters

This is one of the earliest widely cited vendor-documented cases showing quishing succeed specifically against an MFA-related lure: attackers exploiting the fact that MFA enrollment/setup notices are routine, expected, and rarely questioned by employees, making them an effective disguise for credential theft. It also demonstrates a specific and repeatable evasion technique: encoding the malicious link as a QR code inside a PDF (rather than a clickable hyperlink) to slide past email/URL-scanning security controls, then explicitly steering victims to scan with personal mobile devices, which typically sit outside corporate EDR, DNS filtering, and conditional-access policies, to complete the compromise on a weaker-security surface. The case is frequently cited in security-awareness training precisely because it operationalizes both the "QR bypasses email filters" and "mobile device bypasses corporate controls" tactics in one real, remediated incident with a clear SOC investigation narrative (QR decode, DevTools network tracing, OSINT domain analysis) that defenders can learn from.

Defenses

  • Verify the actual destination domain before scanning any QR code (hover/preview or use a QR-inspection tool) rather than trusting the visual code alone
  • Never scan work-related QR codes with a personal/mobile device that lacks corporate security controls (EDR, web filtering, conditional access); this was the threat actor's deliberate pivot point
  • Treat urgent 'your MFA must be set up now' messaging as a red flag, especially when delivered as a PDF attachment rather than through native IT/helpdesk channels
  • Report suspicious QR-code emails to security teams immediately so analysts can extract and analyze the embedded URL before wider circulation
  • On confirmed credential compromise, terminate ALL active sessions before resetting passwords (an unclosed session lets the attacker retain access through the password reset)
  • Block the external domains associated with the malicious QR code across the environment and purge the phishing email from all mailboxes
  • Review affected accounts' activity logs for signs of data exfiltration or lateral spread before declaring an incident closed
  • Deploy email/attachment scanning capable of extracting and reputation-checking QR-code payloads inside PDFs, not just link and text scanning
Sources
  • Stories from the SOC: Quishing: Combatting embedded malicious QR codes. LevelBlue Primary. Primary vendor SOC case study, published 2023-10-10 by James Rodriguez (Senior Specialist, Cybersecurity, LevelBlue MDR SOC). Full narrative of the lure, investigation (QR decode, Chrome Inspector network analysis, OSINT on srvc1[.]info), and remediation steps. Live-fetched and content verified to match all claims attributed to it.
  • Stories from the SOC: Quishing: Combatting embedded malicious QR codes (legacy AT&T Cybersecurity mirror). AT&T Cybersecurity Primary. Same article under the pre-rebrand AT&T Cybersecurity domain and branding. LevelBlue is AT&T Cybersecurity's successor brand. Live-fetched via Wayback Machine and confirmed to mirror the primary source verbatim.
  • "Quishing" - The New Trend?. WebCheck Security Secondary. Published 2023-10-27. Discusses and references the same AT&T/LevelBlue MFA-QR-code case as an example of the broader quishing trend, adds no independent new facts. Live-fetched and confirmed to load and accurately summarize the primary case.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target and infrastructure preparation: The threat actor needed a list of employee email addresses at the target organization, consistent with bulk-harvested or purchased corporate contact lists typical of mass phishing rather than individualized OSINT profiling (LevelBlue's write-up describes no per-employee reconnaissance), and registered a disposable, ownership-obscured domain, srvc1[.]info, to host the credential-harvesting page.
Countering Stage 1: Corporate employee email addresses are widely obtainable through data brokers, breach dumps, or predictable naming conventions, and privacy-protected domain registration is legal and hard to police preemptively; the realistic control sits downstream, at delivery and employee reporting, rather than at blocking address harvesting or domain registration itself.
2
Lure construction: Attackers built a PDF styled as an urgent Microsoft/Windows multi-factor-authentication (MFA) setup notice, embedding a malicious QR code rather than a clickable hyperlink, since QR codes are images that typical email-gateway link and text scanners do not decode and inspect the way they do URLs.
Countering Stage 2: Deploy email/attachment security tooling that extracts and reputation-checks QR-code payloads embedded inside PDFs and images, not just links and text, so the QR-in-a-PDF evasion technique is caught at the gateway before it reaches an inbox.
3
Mass delivery: The phishing email carrying the PDF attachment was sent to multiple employees at the customer organization, using urgency language to discourage the recipient from pausing to verify the request.
Countering Stage 3: Train staff that legitimate MFA enrollment is initiated by internal IT/identity systems, never by an unsolicited PDF with a QR code, and give employees a fast, low-friction way to report suspicious QR-code emails, exactly as the customer in this case did before wider harm occurred.
4
Mobile-device pivot: The lure explicitly relied on victims scanning the QR code with a personal phone rather than a link on the managed corporate device, moving the interaction onto a surface that typically sits outside corporate EDR, DNS filtering, and conditional-access controls.
Countering Stage 4: Set policy and technical controls against scanning work-related QR codes with personal or unmanaged devices, and use mobile device management or conditional access so authentication flows must complete on an enrolled, monitored device, closing the exact weaker-security surface the attacker relied on.
5
Credential harvest: Victims who scanned the code landed on a fake Microsoft sign-in page at srvc1[.]info/mcrsft2fasetup/index.html and entered their real usernames and passwords, which were captured by the threat actor.
Countering Stage 5: Verify the destination domain before entering credentials (checking that it matches microsoft.com or the organization's actual identity provider), and deploy phishing-resistant MFA such as FIDO2/WebAuthn hardware security keys, which cannot be relayed through a look-alike page even if a password is typed into it.
6
Objective completion: The threat actor obtained valid credentials for several employees, achieving credential theft and initial-access/account-takeover conditions; LevelBlue's rapid investigation and remediation closed the incident before any confirmed further use, such as data exfiltration or lateral movement, was observed.
Countering Stage 6: On any confirmed credential submission, immediately close all active sessions before resetting passwords (an unclosed session lets the attacker retain access through the reset), purge the phishing email fleet-wide, block the malicious domains, and audit account activity logs for exfiltration or lateral movement before declaring the incident closed, the exact remediation sequence LevelBlue guided the customer through.
Quick Facts
Victim
Unnamed LevelBlue (AT&T Cybersecurity) Managed Detection and Response (MDR/MTDR) customer
Location
Not disclosed (customer identity, industry, and location withheld by LevelBlue in the published case study)
Date
2023-10-10
Impact
Not disclosed. The LevelBlue case study does not state any dollar figure, ransom, fraud loss, or breach-notification cost; impact is described only as compromised credentials for "several users," with no confirmed data exfiltration.
Status
Confirmed
Case Type
Real-World Incident
Related

Related Cases

Hornetsecurity QRishing Attack on US-Based MSP (2023)

Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice…

Incident 2023Read →

FTC Consumer Alert: QR Code Scams (Quishing)

The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…

Incident 2023Read →

UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset

Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset,…

Incident 2024Read →