A particularly insidious cyberattack tactic is bringing North Korean hacker group Kimsuky, according to a recent warning from the Federal Bureau of Investigation (FBI). The state-backed group is reportedly using malicious QR codes in targeted campaigns spearphishing, targeting organizations and institutions in the United States.

Who is in the spotlight?
Kimsuky's activity focuses on organizations engaged in policy analysis, research programs, and issues directly or indirectly related to North Korea. The list of targets includes non-governmental organizations, think tanks, academic institutions, strategic consulting firms, and US government agencies.
The aim of the attacks is not only to steal credentials, but also to collect valuable information, map networks and, in some cases, long-term penetration into sensitive information systems.
See also: Phishing emails mimic DocuSign to distribute malware
What is “quishing” and why does it work?
The use of QR codes in phishing — known as quishing — is not a new technique. However, it remains highly effective. Unlike traditional phishing links, QR codes often bypass email gateway security filters because they do not contain a readily apparent URL
The FBI has previously warned about the abuse of the technique by financially motivated cybercriminals, but now the method is also being adopted by state-sponsored threat actors, which significantly increases the level of risk.

How attackers act
According to the analysis , victims receive emails containing malicious QR codes. By scanning them, the user is redirected through an infrastructure controlled by the attackers. There, is collected technical information about the device, such as the operating system, IP address, system language, and browser type.
The target is then directed to fake login pages that mimic popular services such as Microsoft 365, Google, or corporate VPN gates, with the aim of stealing credentials or login tokens.
See also: MFA is required for logins to the Microsoft 365 admin center
Trustworthiness and social engineering
To increase their success rates, Kimsuky hackers adopt convincing identities. They present themselves as foreign investors, diplomatic officials, think tank researchers , or even organizers international conference.
A typical example is an incident in June 2025, where the group sent an email to a strategic consulting firm, inviting its executives to a non-existent conference, using a QR code for "registration".

Bypassing MFA and stealth penetration
Of particular concern is that quishing attacks can lead to the interception of session tokens, allowing attackers to bypass authentication (MFA). The FBI characterizes these attacks as MFA-resistant, as they originate from unmanaged mobile devices, outside of EDR systems and classic network surveillance.
See also: CrazyHunter ransomware targets healthcare organizations
How can organizations protect themselves?
The FBI recommends a multi-layered defense approach, which includes training staff specifically for QR-based fraud, verifying the origin of each QR code, implementing mobile device management (MDM) solutions, and strictly enforcing MFA in conjunction with additional checks.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, organizations that detect or suspect such attacks are urged to report them immediately to the relevant FBI cybersecurity services or through the IC3 platform, thus contributing to collective defense against increasingly sophisticated threats.
Source: www.bleepingcomputer.com
