logo

North Korean Kimsuky Threat Actors Use Malicious QR Codes to Target Foreign Policy Experts

ID: 7ce0caf7-c90d-59a7-8715-83f2e9797187

STIX ID: report--7ce0caf7-c90d-59a7-8715-83f2e9797187

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2026-01-09

Date Updated: 2026-04-23

Author: Paul Shread

...
...

The FBI warns that Kimsuky, a North Korean threat group, is conducting targeted spearphishing campaigns using malicious QR codes (“Quishing”) to redirect victims to mobile-optimized credential harvesting pages and infrastructure that can steal session tokens and bypass MFA; observed May–June 2025 incidents targeted think tanks, academic institutions, NGOs, and government-related entities with socially engineered emails containing QR codes linking to fake login or questionnaire pages, and the advisory provides mitigation guidance including user training, MDM/URL inspection, phishing-resistant MFA, logging and monitoring, and liaison with FBI field offices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.