logo

FBI Warns of North Korean QR Phishing Campaigns

ID: 928228ef-6c28-5819-a22b-bace0f5e9529

STIX ID: report--928228ef-6c28-5819-a22b-bace0f5e9529

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

...
...

The FBI warned that North Korean APT Kimsuky ran 2025 'quishing' campaigns using QR codes embedded in spear-phishing emails to send victims to mobile-optimized credential-harvesting pages and attacker-controlled redirectors; the technique collects device attributes, enables credential and session-token theft to bypass MFA, and has targeted think tanks, academic institutions, and government entities. The alert lists specific May–June 2025 incidents and recommends layered defenses including user training, QR verification protocols, MDM/endpoint scanning, phishing-resistant MFA, logging/monitoring, and least-privilege practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.