North Korean Kimsuky Threat Actors Use Malicious QR Codes to Target Foreign Policy Experts
ID: 7ce0caf7-c90d-59a7-8715-83f2e9797187
STIX ID: report--7ce0caf7-c90d-59a7-8715-83f2e9797187
Feed Name: The Cyber Express
The FBI warns that Kimsuky, a North Korean threat group, is conducting targeted spearphishing campaigns using malicious QR codes (“Quishing”) to redirect victims to mobile-optimized credential harvesting pages and infrastructure that can steal session tokens and bypass MFA; observed May–June 2025 incidents targeted think tanks, academic institutions, NGOs, and government-related entities with socially engineered emails containing QR codes linking to fake login or questionnaire pages, and the advisory provides mitigation guidance including user training, MDM/URL inspection, phishing-resistant MFA, logging and monitoring, and liaison with FBI field offices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
