The post FBI says North Korea’s Kimsuky APT uses malicious QR codes to spearphish U.S. entities appeared on BitcoinEthereumNews.com. The FBI says Kimsuky APT, aThe post FBI says North Korea’s Kimsuky APT uses malicious QR codes to spearphish U.S. entities appeared on BitcoinEthereumNews.com. The FBI says Kimsuky APT, a

FBI says North Korea’s Kimsuky APT uses malicious QR codes to spearphish U.S. entities

The FBI says Kimsuky APT, a North Korean state-backed hacking group, is using malicious QR codes to break into U.S. organizations linked to North Korea policy.

The warning came in a 2025 FBI FLASH shared with NGOs, think tanks, universities, and government-connected groups. The agency says the targets all share one thing. They study, advise on, or work around North Korea.

According to the FBI, Kimsuky APT is running spearphishing campaigns that rely on QR codes instead of links, a method known as Quishing.

The QR codes hide harmful URLs, and victims almost always scan them with phones, not work computers. That shift lets the attackers slip past email filters, link scanners, and sandbox tools that usually catch phishing.

Kimsuky APT sends QR-based emails to policy and research targets

The FBI says Kimsuky APT used several themed emails in 2025. Each one matched the target’s job and interests. In May, attackers posed as a foreign advisor. They emailed a think tank leader asking for views on recent events on the Korean Peninsula. The email included a QR code that claimed to open a questionnaire.

Later in May, the group posed as an embassy worker. That email went to a senior fellow at a think tank. It asked for input on North Korean human rights. The QR code claimed to unlock a secure drive. That same month, another email pretended to come from a think tank employee. Scanning its QR code sent the victim to Kimsuky APT infrastructure built for malicious activity.

In June 2025, the FBI says the group targeted a strategic advisory firm. The email invited staff to a conference that did not exist. A QR code sent users to a registration page. A register button then pushed visitors to a fake Google login page. That page collected usernames and passwords. The FBI tied this step to credential harvesting activity tracked as T1056.003.

QR scans lead to token theft and account takeover

The FBI says many of these attacks end with session token theft and replay. This allows attackers to bypass multi-factor authentication without triggering alerts. Accounts are taken over quietly. After that, attackers change settings, add access, and keep control. The FBI says compromised mailboxes are then used to send more spearphishing emails inside the same organization.

The FBI notes that these attacks start on personal phones. That puts them outside normal endpoint detection tools and network monitoring. Because of this, the FBI said:-

The FBI urges organizations to reduce risk. The agency says staff should be warned about scanning random QR codes from emails, letters, or flyers. Training should cover fake urgency and impersonation. Workers should verify QR code requests through direct contact before logging in or downloading files. Clear reporting rules should be in place.

The FBI also recommends using:- “phishing-resistant MFA for all remote access and sensitive systems,” and “reviewing access privileges according to the principle of least privilege and regularly audit for unused or excessive account permissions.”

The smartest crypto minds already read our newsletter. Want in? Join them.

Source: https://www.cryptopolitan.com/north-korea-kimsuky-apt-malicious-qr-codes/

Market Opportunity
Aptos Logo
Aptos Price(APT)
$1.939
$1.939$1.939
+1.41%
USD
Aptos (APT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Vitalik Buterin Reaffirms Original 2014 Ethereum Vision With Modern Web3 Technology Stack

Vitalik Buterin Reaffirms Original 2014 Ethereum Vision With Modern Web3 Technology Stack

TLDR: Ethereum proof-of-stake transition and ZK-EVM scaling solutions effectively realize the 2014 sharding vision. Waku evolved from Whisper to power decentralized
Share
Blockonomi2026/01/14 17:17
CME Group to Launch Solana and XRP Futures Options

CME Group to Launch Solana and XRP Futures Options

The post CME Group to Launch Solana and XRP Futures Options appeared on BitcoinEthereumNews.com. An announcement was made by CME Group, the largest derivatives exchanger worldwide, revealed that it would introduce options for Solana and XRP futures. It is the latest addition to CME crypto derivatives as institutions and retail investors increase their demand for Solana and XRP. CME Expands Crypto Offerings With Solana and XRP Options Launch According to a press release, the launch is scheduled for October 13, 2025, pending regulatory approval. The new products will allow traders to access options on Solana, Micro Solana, XRP, and Micro XRP futures. Expiries will be offered on business days on a monthly, and quarterly basis to provide more flexibility to market players. CME Group said the contracts are designed to meet demand from institutions, hedge funds, and active retail traders. According to Giovanni Vicioso, the launch reflects high liquidity in Solana and XRP futures. Vicioso is the Global Head of Cryptocurrency Products for the CME Group. He noted that the new contracts will provide additional tools for risk management and exposure strategies. Recently, CME XRP futures registered record open interest amid ETF approval optimism, reinforcing confidence in contract demand. Cumberland, one of the leading liquidity providers, welcomed the development and said it highlights the shift beyond Bitcoin and Ethereum. FalconX, another trading firm, added that rising digital asset treasuries are increasing the need for hedging tools on alternative tokens like Solana and XRP. High Record Trading Volumes Demand Solana and XRP Futures Solana futures and XRP continue to gain popularity since their launch earlier this year. According to CME official records, many have bought and sold more than 540,000 Solana futures contracts since March. A value that amounts to over $22 billion dollars. Solana contracts hit a record 9,000 contracts in August, worth $437 million. Open interest also set a record at 12,500 contracts.…
Share
BitcoinEthereumNews2025/09/18 01:39
U.S. politician makes super suspicious war stock trade

U.S. politician makes super suspicious war stock trade

The post U.S. politician makes super suspicious war stock trade appeared on BitcoinEthereumNews.com. Representative Gilbert Cisneros of California drew much attention
Share
BitcoinEthereumNews2026/01/14 17:27