North Korean hackers are using malicious QR codes in spear phishing, FBI warns


  • The North Korean group Kimsuky uses QR code phishing to steal credentials
  • Attacks bypass MFA via session token theft and exploit unmanaged mobile devices outside of EDR protection
  • The FBI calls for multi-layered defenses: employee training, QR reporting protocols and mobile device management

North Koreans are targeting US government institutions, think tanks and academia with highly sophisticated QR code phishing or ‘quishing’ attacks that go after their Microsoft 365, Okta or VPN credentials.

This is according to the Federal Bureau of Investigation (FBI), which recently released a new Flash report warning both domestic and international partners about the ongoing campaign.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top