The FBI says Kimsuky APT, a North Korean state-backed hacking group, is using malicious QR codes to break into U.S. organizations linked to North Korea policy. The FBI says Kimsuky APT, a North Korean state-backed hacking group, is using malicious QR codes to break into U.S. organizations linked to North Korea policy.

FBI warns North Korean hackers are using QR codes to breach U.S. policy groups

The FBI says Kimsuky APT, a North Korean state-backed hacking group, is using malicious QR codes to break into U.S. organizations linked to North Korea policy.

The warning came in a 2025 FBI FLASH shared with NGOs, think tanks, universities, and government-connected groups. The agency says the targets all share one thing. They study, advise on, or work around North Korea.

According to the FBI, Kimsuky APT is running spearphishing campaigns that rely on QR codes instead of links, a method known as Quishing.

The QR codes hide harmful URLs, and victims almost always scan them with phones, not work computers. That shift lets the attackers slip past email filters, link scanners, and sandbox tools that usually catch phishing.

Kimsuky APT sends QR-based emails to policy and research targets

The FBI says Kimsuky APT used several themed emails in 2025. Each one matched the target’s job and interests. In May, attackers posed as a foreign advisor. They emailed a think tank leader asking for views on recent events on the Korean Peninsula. The email included a QR code that claimed to open a questionnaire.

Later in May, the group posed as an embassy worker. That email went to a senior fellow at a think tank. It asked for input on North Korean human rights. The QR code claimed to unlock a secure drive. That same month, another email pretended to come from a think tank employee. Scanning its QR code sent the victim to Kimsuky APT infrastructure built for malicious activity.

In June 2025, the FBI says the group targeted a strategic advisory firm. The email invited staff to a conference that did not exist. A QR code sent users to a registration page. A register button then pushed visitors to a fake Google login page. That page collected usernames and passwords. The FBI tied this step to credential harvesting activity tracked as T1056.003.

QR scans lead to token theft and account takeover

The FBI says many of these attacks end with session token theft and replay. This allows attackers to bypass multi-factor authentication without triggering alerts. Accounts are taken over quietly. After that, attackers change settings, add access, and keep control. The FBI says compromised mailboxes are then used to send more spearphishing emails inside the same organization.

The FBI notes that these attacks start on personal phones. That puts them outside normal endpoint detection tools and network monitoring. Because of this, the FBI said:-

The FBI urges organizations to reduce risk. The agency says staff should be warned about scanning random QR codes from emails, letters, or flyers. Training should cover fake urgency and impersonation. Workers should verify QR code requests through direct contact before logging in or downloading files. Clear reporting rules should be in place.

The FBI also recommends using:- “phishing-resistant MFA for all remote access and sensitive systems,” and “reviewing access privileges according to the principle of least privilege and regularly audit for unused or excessive account permissions.”

Claim your free seat in an exclusive crypto trading community - limited to 1,000 members.

Market Opportunity
Union Logo
Union Price(U)
$0.00284
$0.00284$0.00284
-2.97%
USD
Union (U) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

WLFI Bank Charter Faces Urgent Halt as Warren Exposes Trump’s Alarming Conflict of Interest

WLFI Bank Charter Faces Urgent Halt as Warren Exposes Trump’s Alarming Conflict of Interest

BitcoinWorld WLFI Bank Charter Faces Urgent Halt as Warren Exposes Trump’s Alarming Conflict of Interest WASHINGTON, D.C. – March 15, 2025 – In a dramatic escalation
Share
bitcoinworld2026/01/14 06:40
UNI Price Prediction: Targets $5.85-$6.29 by Late January 2026

UNI Price Prediction: Targets $5.85-$6.29 by Late January 2026

The post UNI Price Prediction: Targets $5.85-$6.29 by Late January 2026 appeared on BitcoinEthereumNews.com. Rebeca Moen Jan 13, 2026 13:37 UNI Price Prediction
Share
BitcoinEthereumNews2026/01/14 05:50
The Next Bitcoin Story Of 2025

The Next Bitcoin Story Of 2025

The post The Next Bitcoin Story Of 2025 appeared on BitcoinEthereumNews.com. Crypto News 18 September 2025 | 07:39 Bitcoin’s rise from obscure concept to a global asset is the playbook every serious investor pores over, and it still isn’t done writing; Bitcoin now trades above $115,000, a reminder that the life-changing runs begin before most people are even looking. T The question hanging over this cycle is simple: can a new contender compress that arc, faster, cleaner, earlier, while the window is still open for those willing to move first? Coins still on presales are the ones can repeat this story, and among those coins, an Ethereum based meme coin catches most of the attention, as it’s team look determined to make an impact in today’s market, fusing culture with working tools, with a design built to reward early movers rather than late chasers. If you’re hunting the next asymmetric shot, this is where momentum and mechanics meet, which is why many traders quietly tag this exact meme coin as the best crypto to buy now in a crowded market. Before we dive deeper, take a quick rewind through the case study every crypto desk knows by heart: how Bitcoin went from about $0.0025 to above $100,000, and turned a niche experiment into the story that still sets the bar for everything that follows. Bitcoin 2010-2025 Price History Back to first principles: a strange internet money appears in 2010 and then, step by step, rewires the entire market, Bitcoin’s arc from about $0.0025 to above $100,000 is the case study every desk still cites because it proves one coin can move the entire game. In 2009 almost no one guessed the destination; launched on January 3, 2009, Bitcoin picked up a price signal in 2010 when the pizza trade valued BTC near $0,0025 while early exchange quotes lived at fractions of…
Share
BitcoinEthereumNews2025/09/18 12:41