FBI Alerts to North Korean Hackers Using QR Codes in Phishing Attacks
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The U.S. Federal Bureau of Investigation (FBI) has recently alerted organizations about the Kimsuky group, a North Korean state-sponsored threat actor, utilizing malicious QR codes in spear-phishing campaigns. This advisory, released on January 9, 2026, highlights how Kimsuky has targeted think tanks, academic institutions, and both U.S. and foreign government entities since 2025, employing a technique referred to as ‘quishing.’
Kimsuky, also known as APT43, Black Banshee, and Velvet Chollima, has a history of orchestrating sophisticated spear-phishing attacks designed to bypass email authentication protocols. The group has been noted for exploiting misconfigured Domain-based Message Authentication, Reporting, and Conformance (DMARC) records to send deceptive emails that appear to originate from legitimate domains.
In May and June 2025, the FBI observed Kimsuky actors executing several phishing attempts, including spoofing emails from foreign advisors and embassy employees. In one instance, they sent an email requesting insights from a think tank leader, embedding a QR code that led to a questionnaire. In another case, they impersonated an embassy employee, providing a QR code that purportedly granted access to a secure drive.
These QR codes redirect victims to malicious sites, enabling attackers to harvest sensitive information, including Google account credentials. The FBI noted that such operations often result in session token theft, allowing attackers to bypass multi-factor authentication and hijack cloud identities.
The use of QR codes in phishing attacks is particularly concerning as it shifts the attack vector from secured enterprise environments to potentially vulnerable mobile devices. This tactic is now regarded as a high-confidence identity intrusion vector, making it essential for organizations to enhance their security measures against such threats.
Understanding Quishing Risks
The recent trend of ‘quishing’ highlights a growing cybersecurity risk where attackers leverage QR codes to bypass traditional security measures. Organizations must be vigilant as these attacks can lead to significant data breaches and identity theft.
As Kimsuky continues to evolve its tactics, it is crucial for users and organizations to recognize the signs of phishing attempts, especially those involving QR codes. Regular training and awareness programs can help mitigate the risks associated with these sophisticated attacks.
Key Takeaways
- Educate employees about the risks of scanning QR codes from unknown sources to prevent falling victim to phishing attacks.
- Implement strict email authentication protocols, including DMARC, to reduce the likelihood of spoofed emails reaching users.
- Encourage the use of secure devices for accessing sensitive information and discourage the use of personal mobile devices for work-related tasks.
- Monitor for unusual account activity and establish protocols for reporting suspected phishing attempts.
- Regularly update security software and conduct training sessions on identifying phishing tactics, including quishing.
Key Terms & Concepts
- Kimsuky: In this article, Kimsuky refers to a North Korean state-sponsored hacking group known for spear-phishing campaigns.
- Quishing: Quishing is a type of phishing attack that uses QR codes to trick victims into providing sensitive information.
- DMARC: DMARC stands for Domain-based Message Authentication, Reporting, and Conformance, a protocol used to prevent email spoofing.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.