Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes

The North Korean state-sponsored espionage group Kimsuky has targeted government organizations, think tanks, and academic institutions.

North Korea

The North Korean APT Kimsuky has been targeting government entities, academic institutions, and think tanks with spear-phishing emails containing malicious QR codes, the FBI warns.

Referred to as quishing, this type of attack involves phishing emails containing QR codes with embedded malicious URLs that force the victims to use a mobile device instead of their corporate computer.

The phishing technique results in the bypass of traditional email security controls, the FBI notes in a fresh alert (PDF).

“Quishing campaigns commonly deliver QR images as email attachments or embedded graphics, evading URL inspection, rewriting, and sandboxing,” the FBI says.

Once the victim scans the malicious QR code, they are redirected through attacker-controlled domains designed to collect device information such as user-agent, OS, screen size, IP address, and locale.

This information allows the attackers to serve their victims mobile-optimized phishing pages mimicking legitimate Microsoft 365, Okta, or VPN portals, the FBI notes.

Advertisement. Scroll to continue reading.

By stealing session cookies and mounting replay attacks, the hackers bypass multi-factor authentication (MFA) and hijack their victim’s cloud identities, the Bureau says.

After the initial intrusion, the attackers establish persistence and abuse the compromised identity to propagate secondary spear-phishing attacks.

“Because the compromise path originates on unmanaged mobile devices outside normal Endpoint Detection and Response (EDR) and network inspection boundaries, Quishing is now considered a high-confidence, MFA-resilient identity intrusion vector in enterprise environments,” the FBI’s alert reads.

In May and June 2025, Kimsuky was seen employing quishing in four attacks targeting think tanks and a strategic advisory firm.

The email messages spoofed a foreign advisor, an embassy employee, and a think tank employee, and invited the employees of the advisory firm to a non-existent conference.

Active since at least 2012, Kimsuky is a state-sponsored espionage group focused on intelligence collection from entities in the US, Japan, and South Korea.

Also known as APT43, Velvet Chollima, Emerald Sleet, TA406, and Black Banshee, the APT was sanctioned by the US in 2023, for activities facilitating sanction evasion and supporting Pyongyang’s weapons of mass destruction programs.

Related: North Korea’s Digital Surge: $2B Stolen in Crypto as Amazon Blocks 1,800 Fake IT Workers

Related: React2Shell Attacks Linked to North Korean Hackers

Related: Leader of North Korean Hackers Sanctioned by EU

Related: North Korean Hackers Distributed Android Spyware via Google Play

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Trellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.

Mike Marshall has been appointed State Chief Information Security Officer at the California Department of Technology.

Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.