HomeSecurityPhishing: Kimsuky hackers use malicious QR codes

Phishing: Kimsuky hackers use malicious QR codes

A particularly insidious cyberattack tactic is bringing North Korean hacker group Kimsuky, according to a recent warning from the Federal Bureau of Investigation (FBI). The state-backed group is reportedly using malicious QR codes in targeted campaigns spearphishing, targeting organizations and institutions in the United States.

Phishing Kimsuky QR codes

Who is in the spotlight?

Kimsuky's activity focuses on organizations engaged in policy analysis, research programs, and issues directly or indirectly related to North Korea. The list of targets includes non-governmental organizations, think tanks, academic institutions, strategic consulting firms, and US government agencies.

The aim of the attacks is not only to steal credentials, but also to collect valuable information, map networks and, in some cases, long-term penetration into sensitive information systems.

See also: Phishing emails mimic DocuSign to distribute malware

What is “quishing” and why does it work?

The use of QR codes in phishing — known as quishing — is not a new technique. However, it remains highly effective. Unlike traditional phishing links, QR codes often bypass email gateway security filters because they do not contain a readily apparent URL

The FBI has previously warned about the abuse of the technique by financially motivated cybercriminals, but now the method is also being adopted by state-sponsored threat actors, which significantly increases the level of risk.

Phishing: Kimsuky hackers use malicious QR codes

How attackers act

According to the analysis , victims receive emails containing malicious QR codes. By scanning them, the user is redirected through an infrastructure controlled by the attackers. There, is collected technical information about the device, such as the operating system, IP address, system language, and browser type.

The target is then directed to fake login pages that mimic popular services such as Microsoft 365, Google, or corporate VPN gates, with the aim of stealing credentials or login tokens.

See also: MFA is required for logins to the Microsoft 365 admin center

Trustworthiness and social engineering

To increase their success rates, Kimsuky hackers adopt convincing identities. They present themselves as foreign investors, diplomatic officials, think tank researchers , or even organizers international conference.

A typical example is an incident in June 2025, where the group sent an email to a strategic consulting firm, inviting its executives to a non-existent conference, using a QR code for "registration".

Phishing: Kimsuky hackers use malicious QR codes

Bypassing MFA and stealth penetration

Of particular concern is that quishing attacks can lead to the interception of session tokens, allowing attackers to bypass authentication (MFA). The FBI characterizes these attacks as MFA-resistant, as they originate from unmanaged mobile devices, outside of EDR systems and classic network surveillance.

See also: CrazyHunter ransomware targets healthcare organizations

How can organizations protect themselves?

The FBI recommends a multi-layered defense approach, which includes training staff specifically for QR-based fraud, verifying the origin of each QR code, implementing mobile device management (MDM) solutions, and strictly enforcing MFA in conjunction with additional checks.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Finally, organizations that detect or suspect such attacks are urged to report them immediately to the relevant FBI cybersecurity services or through the IC3 platform, thus contributing to collective defense against increasingly sophisticated threats.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS