North Korean hackers use malicious QR codes for spear phishing, FBI warns


  • North Korean Kimsuky Group Uses QR Code Phishing to Steal Credentials
  • Attacks bypass MFA via session token theft, exploiting unmanaged mobile devices outside of EDR protections.
  • FBI recommends multi-layered defense: employee training, QR reporting protocols and mobile device management

The North Koreans are targeting U.S. government institutions, think tanks and academia with highly sophisticated QR code phishing attacks, or “quishing” attacks, targeting their Microsoft 365, Okta or VPN credentials.

This is according to the Federal Bureau of Investigation (FBI), which recently published a new Flash report, warning national and international partners against the ongoing campaign.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top