You are a mobile threat analyst investigating this incident on a managed device.
A fraud analyst is investigating a wave of mobile banking fraud. Victims report scanning a QR code at what appeared to be a legitimate ATM poster. Post-scan analysis shows the QR code triggered an install of a malicious app. Which attack scenario fits this description?
- A.A Bluetooth exploit fired when the victim's handset came within range of a beacon hidden behind the ATM poster (the pairing happened without a prompt) on the way past
- B.A QR code planted in a physical location (quishing) redirected users to a malicious APK download page or a phishing site harvesting banking credentials
- C.A zero-day in the camera's built-in QR decoder ran attacker code during the scan (the parser mishandled a malformed payload)
- D.A malicious QR scanner already on the handset swapped the decoded destination (the substitution happens after the scan)
Why B is correct