QRLJacking – New Social Engineering Attack Vector

QRLJacking or Quick Response Code Login Jacking is a simple-but-nasty attack vector affecting all the applications that relays on “Login with QR code” feature as a secure way to login into accounts which aims for hijacking users session by attackers.

This attack vector is made by Mohamed Abdelbasset Elnouby (@SymbianSyMoh) security researcher from Seekurity Labs.
Using QRLJacking you can use to hijack session for following services:

Chat Applications:

WhatsApp, WeChat, Line, Weibo, QQ Instant Messaging

Mailing Services:

QQ Mail (Personal and Business Corporate), Yandex Mail


Alibaba, Aliexpress, Taobao, Tmall,, Alimama, Taobao Trips

Online Banking:

AliPay, Yandex Money, TenPay

Passport Services “Critical”:

Yandex Passport (Yandex Mail, Yandex Money, Yandex Maps, Yandex Videos, etc…)

Mobile Management Software:


Other Services:

MyDigiPass, Zapper & Zapper WordPress Login by QR Code plugin, Trustly App, Yelophone, Alibaba Yunos

If you want to try it and check how to prepare everything, you can check official OWASP’s GitHub repository for QRLJacking Attack Vector

Here’s also demonstration video:

%d bloggers like this: