QR codes a powerful new phishing weapon in hands of Pyongyang cyberspies
ID: 3afb0973-66c9-574f-8de7-0324b3825637
STIX ID: report--3afb0973-66c9-574f-8de7-0324b3825637
Feed Name: The Register (Security)
The FBI warns that DPRK-linked Kimsuky operators have been embedding malicious URLs in QR codes ("quishing") delivered via spear-phishing emails; when scanned, victims are redirected to fake portals (Microsoft 365, Okta, VPN) where credentials and session tokens are stolen and reused to bypass MFA and persist in networks. Campaigns observed in 2025 targeted think tanks, academic institutions, and government organizations connected to North Korea policy, exploiting the limited visibility and controls over unmanaged mobile devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
