Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What happens when attackers place malicious QR codes…
Cyber Security

What happens when attackers place malicious QR codes alongside legitimate PDF annotations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Cyber Security

The annotations act as camouflage. They make the document appear authentic, distract both users and security tools, and shift attention away from the QR code that leads to the phishing site. In practice, this creates a layered deception where the trusted elements are clean, the visible content looks safe, and the actual threat is hidden behind an extra step.

How the deception works

Placed together, the annotation layer and the QR code create a visual stack that exploits trust in the document format itself. The PDF looks edited in a normal, routine way, so the malicious code benefits from the same legitimacy cues users expect from comments, highlights, signatures, or review notes. That makes the QR code easier to ignore until it has already redirected the victim.

This pattern is effective because people tend to process the visible annotation as the “reason” the document looks active, while the QR code becomes a secondary object inside the page. The attacker is not trying to hide the document completely, only to make the harmful element feel like part of ordinary document collaboration.

For deeper case-based context on how attackers hide abuse behind trusted content and infrastructure, see The 52 NHI breaches Report and Nx Package Attack, 2,300+ Credentials Leaked.

Why this bypasses ordinary scrutiny

PDF annotations are a useful camouflage layer because they are expected to be interactive, user-generated, and visually noisy. Security review often focuses on the main document content, embedded links, or obvious attachments, so a QR code that sits beside an apparently harmless annotation can slip past both casual review and automated inspection.

The extra step matters. If a user must first scan the code and then land on a phishing site, the malicious intent is separated from the document by a small but effective interaction gap. That gap lowers suspicion, especially when the surrounding annotations suggest the file is a routine draft, review copy, or internal note.

Attackers also benefit from rendering differences. Some tools flatten, reorder, or partially interpret annotations, which can hide the relationship between the annotation and the QR image or make the malicious element less prominent in previews. When that happens, the document can look clean in one viewer and deceptive in another.

For related threat patterns and defensive framing, review CISA cyber threat advisories and MITRE ATLAS adversarial AI threat matrix for the broader principle of hiding malicious action inside normal-looking workflows and trusted interfaces.

What practitioners should check before they trust the file

Scan the PDF structure, not just the visible page. The important question is whether the file contains hidden layers, unexpected external links, or annotations that serve no business purpose but do affect where the user is sent after scanning. If a QR code appears in a review document, treat it as an active redirect until you verify its target out of band.

What to verify: confirm the QR destination with a safe decoder, inspect whether the annotation is actually part of the document workflow, and compare the rendered page across multiple viewers. If the annotated element changes meaning depending on the viewer, assume the file is being used to create ambiguity.

What changes at scale: the same trick can be reused across many documents because it exploits user habit more than a technical flaw. That means triage should prioritise files that mix trusted business formats with embedded navigation objects, especially when the document originated outside the organisation or arrived through an informal channel.

Practitioner takeaway: The real control point is not “can the PDF be opened”, but “does every interactive element have a justified, inspected destination that matches the business purpose of the file”.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1204 — User ExecutionThe QR code depends on a user action that triggers the phishing path.
T1583 — Acquire InfrastructureThe QR code resolves to attacker-controlled phishing infrastructure.
Recommendation — Hunt for files that rely on user interaction to launch malicious redirection. Trace the destination infrastructure and block newly observed phishing hosts.
CIS Controls v88 — Audit Log ManagementDocument and viewer activity should be logged to support investigation of suspicious scans and opens.
Recommendation — Log document access and QR redirect events so suspicious files can be investigated quickly.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org