{"id":131703,"date":"2025-10-29T18:16:57","date_gmt":"2025-10-29T18:16:57","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=131703"},"modified":"2025-10-29T18:17:01","modified_gmt":"2025-10-29T18:17:01","slug":"emerging-cyber-threats","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/","title":{"rendered":"Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses"},"content":{"rendered":"\n<p>Cybersecurity experts at ANY.RUN recently unveiled <a href=\"https:\/\/any.run\/cybersecurity-blog\/malware-trends-report-q3-2025\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new_malware_tactics&amp;utm_content=blog&amp;utm_term=291025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>alarming trends<\/strong><\/a> in how attackers are exploiting everyday technologies to bypass security operations centers (SOCs).<\/p>\n\n\n\n<p>They dissected tactics like QR code phishing, <a href=\"https:\/\/cybersecuritynews.com\/clickfix-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">ClickFix social engineering<\/a>, and Living Off the Land Binaries (LOLBins), showing how these methods evade traditional defenses.<\/p>\n\n\n\n<p>As <a href=\"https:\/\/any.run\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new_malware_tactics&amp;utm_content=landing&amp;utm_term=291025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>threats grow<\/strong><\/a> more sophisticated, SOC teams face mounting pressure to adapt, with low detection rates risking severe breaches. Drawing from analyses of real-world samples, the session emphasized interactive tools and real-time intelligence as vital countermeasures.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-clickfix-attacks-mastering-human-deception\"><strong>ClickFix Attacks: Mastering Human Deception<\/strong><\/h3>\n\n\n\n<p><a href=\"https:\/\/intelligence.any.run\/analysis\/lookup\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new_malware_tactics&amp;utm_content=lookup_query&amp;utm_term=291025#{%22query%22:%22threatName:%5C%22ClickFix%5C%22%22,%22dateRange%22:60}\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ClickFix attacks<\/a> stand out for their reliance on user interaction, turning routine verifications into malware gateways. Attackers send phishing emails mimicking trusted sites, like booking platforms, complete with fake CAPTCHAs.<\/p>\n\n\n\n<p>Once a victim clicks, a malicious PowerShell script hijacks the clipboard unnoticed, prompting the user to paste and execute it via a system dialog.<\/p>\n\n\n\n<p>This multi-stage ploy thrives on deception: double spoofing creates convincing replicas, while manual steps foil automated scanners.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhM7BvKXH9zcp0djXpQzRkbkezbM7JQzpOzTvNTXEbwZz_0xKmpj6TZKtCAXBNMP-jd3bML6kwCfRgy7pKwowQcz8jXmDQff1GsMJ8GfgfZAur-uZYBX1b4MyDgonNreBOIj4k7Bas6Hok_2wqhM9tlyez4RXsICOqRQpxJZj4RpLWUBIuT4uVmckR09Ape\/s16000\/Clickfix%20attack.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p><strong><a href=\"https:\/\/app.any.run\/tasks\/1d274110-4351-43c2-a6e7-21d326221efd\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new_malware_tactics&amp;utm_content=task&amp;utm_term=291025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Sandbox analyses reveal<\/a><\/strong> how execution deploys stealers like Lumma or <a href=\"https:\/\/cybersecuritynews.com\/asyncrat-dark-mode\/\" target=\"_blank\" rel=\"noreferrer noopener\">AsyncRAT<\/a>, plus ransomware, establishing persistence through startup files.<\/p>\n\n\n\n<p>Traditional tools falter at CAPTCHAs, but interactive sandboxes simulate human actions, exposing the full chain from initial click to payload delivery in seconds.<\/p>\n\n\n\n<p>Without such capabilities, SOCs miss threats that blend seamlessly into user workflows, leading to credential theft and system compromise.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-phishkit-attacks-qr-codes-as-stealth-vectors\"><strong>PhishKit Attacks: QR Codes as Stealth Vectors<\/strong><\/h3>\n\n\n\n<p>Phishing kits, or phishkits, have evolved into dark web staples, empowering novices to launch pro-level campaigns against giants like Microsoft and Google.<\/p>\n\n\n\n<p>The latest twist integrates QR codes into PDF attachments disguised as DocuSign docs, directing scans to mobile devices where phishing cues hide on small screens.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEivrUpdGwsJlEmTG9rjQd40cuw8ZyDz0n5iR9bKcWohpay0pACrQBj7IdkFuW7uXukk-gUszB5ZoKz0m-Nre_GcD3S_aKqa7OAPKe9TwtgkcTlYKsD6hXMKBXwvsvZjNRuIn0NDGjQKy-ifCXyY5m7LI0erA7XXtrPSLiXQsA9_6bvsA0pXmzTcQlCI4jkP\/s16000\/LOLBins.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p>These kits incorporate AI-generated lures, multi-stage checks, and CAPTCHAs like Cloudflare Turnstile, culminating in fake login pages for credential harvesting.<\/p>\n\n\n\n<p>ANY.RUN&#8217;s <a href=\"https:\/\/app.any.run\/tasks\/650ae35c-e319-4779-81f2-e6490038a382\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new_malware_tactics&amp;utm_content=task&amp;utm_term=291025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>automated detonation<\/strong><\/a> extracts QR links, solves challenges, and traces the kill chain, revealing ties to groups like <a href=\"https:\/\/cybersecuritynews.com\/clickfix-and-multi-stage-frameworks\/\" target=\"_blank\" rel=\"noreferrer noopener\">Storm-1747<\/a>.<\/p>\n\n\n\n<p>Many defenses overlook QR content, allowing evasion, but advanced sandboxes handle this autonomously, cutting Tier 1 workloads by 20%. As phishkits proliferate, targeting regions via localized lures, SOCs must prioritize QR scanning to curb widespread campaigns.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-lolbins-weaponizing-trusted-tools\"><strong>LOLBins: Weaponizing Trusted Tools<\/strong><\/h3>\n\n\n\n<p>LOLBins exploit Windows&#8217; own utilities, PowerShell, mshta.exe, and cmd.exe to mask malice as routine operations. A phishing .lnk file might invoke mshta via PowerShell to fetch payloads from remote servers, downloading decoy PDFs to obscure the real stealer, like <a href=\"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/\" target=\"_blank\" rel=\"noreferrer noopener\">DeerStealer<\/a>.<\/p>\n\n\n\n<p>This &#8220;living off the land&#8221; approach evades whitelists and antivirus software by mimicking admin tasks, leaving faint forensic traces.<\/p>\n\n\n\n<p>Behavioral <strong><a href=\"https:\/\/app.any.run\/tasks\/02dd6096-b621-49a0-a7ef-4758cc957c0f\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new_malware_tactics&amp;utm_content=task&amp;utm_term=291025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">analysis in sandboxes<\/a><\/strong> uncovers connections to C2 servers and persistence mechanisms, distinguishing abuse from legitimacy.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgxWq6kSowmnU9uO3DmSvxx2kyZaynWQi1ZrZJzGkRu6PXe_PJtmafpSVA76i0iPF_CXM1psz39_bxSfVTfPkQq_nnwh7Bdg8fWBMfSPzhH9o1s3KXM5MwtCpHtSt2dInXGR3nagoj9EjSAUPkK3s6c2O2on-bDYLs5_-5J2lzQQpeLQu7aiqywelFuJueN\/s16000\/PhishKit%20Attacks.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p>Without context from global investigations, alerts trigger false positives. Threat intelligence feeds, pulling fresh IOCs from thousands of sessions, enable real-time blocking, slashing response times.<\/p>\n\n\n\n<p>The tactics employed by ClickFix, including interactivity, QR obfuscation, and LOLBin stealth, highlight the limitations of relying solely on automation.<\/p>\n\n\n\n<p><a href=\"https:\/\/any.run\/contacts\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new_malware_tactics&amp;utm_content=contacts&amp;utm_term=291025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ANY.RUN&#8217;s solutions<\/a>, which combine interactive analysis with shared intelligence, enhance detection rates by 88% in under a minute and reduce mean time to resolve (MTTR) by 21 minutes.<\/p>\n\n\n\n<p>Security Operations Centers (SOCs) that implement these solutions report a 30% decrease in escalations and a tripling of efficiency, thereby strengthening their defenses against an increasingly relentless adversary landscape.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 88%,rgb(169,184,195) 100%)\"><strong>Enhance your SOC Performance With Interactive Sandbox Threat Intelligence Lookup and Feeds => <a href=\"https:\/\/any.run\/demo\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new_malware_tactics&amp;utm_content=demo&amp;utm_term=291025\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try Now<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity experts at ANY.RUN recently unveiled alarming trends in how attackers are exploiting everyday technologies to bypass security operations centers (SOCs). They dissected tactics like QR code phishing, ClickFix social engineering, and Living Off the Land Binaries (LOLBins), showing how these methods evade traditional defenses. As threats grow more sophisticated, SOC teams face mounting pressure [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":131707,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,56,33],"tags":[149,151],"class_list":{"0":"post-131703","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-cyberpedia","9":"category-malware","10":"tag-cyber-security","11":"tag-cyber-security-news"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses<\/title>\n<meta name=\"description\" content=\"Cybersecurity experts at ANY.RUN recently unveiled alarming trends in how attackers are exploiting everyday technologies to bypass security operations centers (SOCs).\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses\" \/>\n<meta property=\"og:description\" content=\"Cybersecurity experts at ANY.RUN recently unveiled alarming trends in how attackers are exploiting everyday technologies to bypass security operations centers (SOCs).\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-29T18:16:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-10-29T18:17:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1848\" \/>\n\t<meta property=\"og:image:height\" content=\"1046\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Balaji N\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/balaji_gbh\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Balaji N\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses","description":"Cybersecurity experts at ANY.RUN recently unveiled alarming trends in how attackers are exploiting everyday technologies to bypass security operations centers (SOCs).","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/","og_locale":"en_US","og_type":"article","og_title":"Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses","og_description":"Cybersecurity experts at ANY.RUN recently unveiled alarming trends in how attackers are exploiting everyday technologies to bypass security operations centers (SOCs).","og_url":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2025-10-29T18:16:57+00:00","article_modified_time":"2025-10-29T18:17:01+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp","type":"","width":"","height":""},{"width":1848,"height":1046,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp","type":"image\/jpeg"}],"author":"Balaji N","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp","twitter_creator":"@https:\/\/twitter.com\/balaji_gbh","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Balaji N","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/"},"author":{"name":"Balaji N","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/0ad7770df28fe608567609e4ba1c4da2"},"headline":"Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses","datePublished":"2025-10-29T18:16:57+00:00","dateModified":"2025-10-29T18:17:01+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/"},"wordCount":555,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/#primaryimage"},"thumbnailUrl":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp?w=1848&resize=1848,1046&ssl=1","keywords":["cyber security","cyber security news"],"articleSection":["Cyber Security News","CyberPedia","Malware"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/","url":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/","name":"Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/#primaryimage"},"thumbnailUrl":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp?w=1848&resize=1848,1046&ssl=1","datePublished":"2025-10-29T18:16:57+00:00","dateModified":"2025-10-29T18:17:01+00:00","description":"Cybersecurity experts at ANY.RUN recently unveiled alarming trends in how attackers are exploiting everyday technologies to bypass security operations centers (SOCs).","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/#primaryimage","url":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp?w=1848&resize=1848,1046&ssl=1","contentUrl":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp?w=1848&resize=1848,1046&ssl=1","width":"1848","height":"1046"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/0ad7770df28fe608567609e4ba1c4da2","name":"Balaji N","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8075aac45cdbf0aae6572d8039978c587715d33d6b330539092189c91804f031?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8075aac45cdbf0aae6572d8039978c587715d33d6b330539092189c91804f031?s=96&d=mm&r=g","caption":"Balaji N"},"description":"BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief &amp; Co-Founder - Cyber Security News &amp; GBHackers On Security.","sameAs":["https:\/\/www.linkedin.com\/company\/cybersecurity-news\/","https:\/\/x.com\/https:\/\/twitter.com\/balaji_gbh"],"url":"https:\/\/cybersecuritynews.com\/author\/balaji\/"}]}},"jetpack_featured_media_url":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSIn-3ZntdY8ZNDWGXe96dcuzWgtiqo3Avx8bP_ESAwSN4vTRyQd5tQ14Ppu39eKePVyXye96V7E91ZezBt7VZo-Zff5sL2qhGG0oFH_V1m2GIoeSJbP3hhWVwEHcbLV543byYbfgaP85-FaZMishAWIlVQrKCby2lABM4p_eojNnHMqmAQnEMrMp9PFwx\/s16000\/Feature%20(1).webp?w=1848&resize=1848,1046&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/131703","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=131703"}],"version-history":[{"count":1,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/131703\/revisions"}],"predecessor-version":[{"id":131706,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/131703\/revisions\/131706"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/131707"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=131703"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=131703"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=131703"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}