North Korean hackers use malicious QR codes in phishing, FBI warns



  • North Korean group Kimsuky uses phishing with QR codes to steal credentials
  • Attacks bypass MFA by stealing session tokens, exploiting unmanaged mobile devices outside EDR protections
  • FBI Urges Multi-Level Defense: Employee Training, QR Reporting Protocols and Mobile Device Management

The North Koreans are targeting US government institutions, think tanks and academics with highly sophisticated QR code phishing or “quishing” attacks, seeking their Microsoft 365, Okta or VPN credentials.

This is according to the Federal Bureau of Investigation (FBI), which recently released a new Flash report, warning its domestic and international partners about the ongoing campaign.



Leave a Comment

Your email address will not be published. Required fields are marked *