logo

FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs

ID: baefccdc-6422-505b-91db-6683156c45a7

STIX ID: report--baefccdc-6422-505b-91db-6683156c45a7

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-01-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The FBI warns that North Korean state-sponsored APT Kimsuky (APT43) is using malicious QR codes in targeted spearphishing campaigns against U.S. policy, research, academic, and government organizations to fingerprint devices and harvest credentials or session tokens—enabling MFA bypass; the alert includes examples of lures and recommends employee training, QR-source verification, mobile device management, strict MFA enforcement, and reporting to the FBI or IC3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.