Top 2026 2FA & AiTM Detection: QR Code (Quishing) and HTML-Smuggled AiTM Credent
Detects inbound emails containing malicious QR codes (quishing) or HTML smuggling payloads designed to facilitate credential harvesting (AiTM). The rule identifies suspicious attachments, HTML-based obfuscation (e.g., atob, Blob) in email bodies, and QR-code-themed image attachments, filtering out internal communications.
Sigma

