logo

North Korean Threat Actor Spreads Malware via QR Codes

ID: 0cf7dc2a-630a-5a22-926d-2511c8401c5b

STIX ID: report--0cf7dc2a-630a-5a22-926d-2511c8401c5b

Feed Name: KnowBe4 Blog

Threat Score
82/100

Date Published: 2026-01-07

Date Updated: 2026-04-28

Author: KnowBe4 Team

...
...

Kimsuky (a North Korean APT) is using QR-code phishing pages that impersonate delivery services to coerce victims into installing malicious mobile apps; researchers found four malicious applications served from 27.102.137.181 and link the activity to smishing/phishing initial access. The technique allows the actor to bypass desktop defenses by moving victims to mobile devices and relies on social engineering to get users to install the malware, posing a targeted threat to organizations and individuals receiving unsolicited delivery notifications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.