Quishing
Quishing is phishing that delivers its link inside a QR code. The code is an image, so the URL is not text that a mail gateway can rewrite, rate or block, and the scan usually happens on a personal phone that sits outside every network control the organisation operates.
The evasion is structural rather than clever. Link inspection, reputation scoring and rewriting all operate on text in the message body; an image carries none. The message that surrounds the code can be short, clean and free of the wording that content filters look for, which also helps it past the layer that would otherwise flag it.
The second half is the device change. Scanning moves the victim from a managed laptop, behind a web proxy and an endpoint agent, to a phone with none of them. The destination is loaded in a mobile browser where the address is truncated, and if the target authenticates there, the resulting session is one the organisation cannot see. Codes printed on paper and left in offices, car parks or on top of existing signage remove the mail channel entirely, so DMARC and sender authentication contribute nothing.
Detection therefore has to happen after the fact, in the identity logs rather than in the mail platform: an authentication from an unmanaged device shortly after a message arrived. In an exercise we include this channel specifically to test whether that correlation exists, because most estates find it only when someone reports the message. It runs as one of the scenarios in the phishing simulation that includes QR delivery in the scenario set, alongside conventional phishing.