logo

Kimsuky Expands Mobile Attacks with Weaponized QR Codes

ID: 1d7f1385-2157-5370-8a9b-85dd5b36d144

STIX ID: report--1d7f1385-2157-5370-8a9b-85dd5b36d144

Feed Name: Zimperium Blog

Threat Score
78/100

Date Published: 2025-12-19

Date Updated: 2026-05-01

...
...

Kimsuky, a North Korea-linked threat actor, is conducting an active campaign that uses weaponized QR codes and phishing websites to distribute trojanized Android apps acting as Remote Access Trojans; these samples use encrypted payloads that are decrypted and loaded at runtime to evade static detection and target mobile users and enterprises. Zimperium highlights the threat of QR-based delivery, notes that its Mobile Threat Defense and Mobile Runtime Protection detect and block these attacks (reporting 90% detection of public IOCs via on-device dynamic detection), and emphasizes the importance of runtime and QR-code protections to mitigate this mobile-native attack vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.