logo

FBI Warns of Kimsuky Actors Leverage Malicious QR Codes to Target U.S. Organizations

ID: 3cc66267-9eae-5a10-a58f-b4f73420b5bb

STIX ID: report--3cc66267-9eae-5a10-a58f-b4f73420b5bb

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-01-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

North Korean APT Kimsuky is running QR-code-based spearphishing ("quishing") campaigns targeting U.S. think tanks, NGOs, academics, and government-linked entities focused on North Korea. Scanned QR codes route victims through attacker-controlled redirectors that fingerprint the device and deliver mobile-optimized fake login portals (Microsoft 365, Google, Okta, VPNs); harvested credentials and session cookies are used to bypass MFA, achieve account takeover, enable mailbox abuse and persistent cloud access, and propagate additional QR lures from compromised accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.