The FBI, CISA, and NSA have issued warnings about a surge in spear-phishing campaigns conducted by the North Korean state-sponsored threat group Kimsuky (APT43), which leverage malicious QR codes—known as quishing—to target high-value individuals in government, academia, think tanks, and foreign policy organizations. These attacks embed QR codes in phishing emails, which, when scanned, redirect victims to credential harvesting sites or initiate malware downloads, often bypassing traditional email security controls and exploiting the relative insecurity of mobile devices. Kimsuky’s campaigns are characterized by highly personalized lures, extensive reconnaissance, and a focus on intelligence gathering, with observed targeting of Microsoft 365 and Google Workspace accounts.
Quishing attacks are effective because QR codes can evade standard email security measures such as URL inspection and sandboxing, and they obscure the true destination from the user. Once a victim scans the QR code, attackers can collect device and identity attributes, present mobile-optimized phishing pages impersonating legitimate portals (such as Microsoft 365 or Okta), and steal credentials or session tokens—sometimes bypassing multi-factor authentication. The campaigns have been observed globally and represent a significant evolution in Kimsuky’s social engineering and credential theft operations, prompting urgent mitigation guidance from U.S. federal agencies and security researchers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By January 11, 2026, the FBI, CISA, and NSA had issued a joint advisory describing Kimsuky's quishing operations against Microsoft 365, Google Workspace, Okta, and other SSO or VPN portals. The agencies recommended mitigations including phishing-resistant MFA, QR-email detection, infrastructure blocking, and monitoring for anomalous mobile authentications.
On or before January 10, 2026, the FBI warned that the North Korea-linked group Kimsuky was using QR codes in spear-phishing emails to evade email defenses and harvest credentials from mobile users. The alert described targeting of government entities, think tanks, NGOs, and academic institutions, and warned of possible MFA bypass through session token theft and replay.
US authorities said Kimsuky's malicious QR-code spear-phishing campaign had been observed since late 2025 across multiple regions. Confirmed incidents resulted in credential compromise and unauthorized access to internal resources.
In June 2025, Kimsuky continued the QR-code phishing activity using invitations to non-existent conferences and other policy-themed lures. At least some victims were redirected to counterfeit login pages, including a fraudulent Google sign-in page.
In May 2025, Kimsuky used malicious QR codes in spear-phishing emails targeting government, think tank, and academic victims. Lures included messages posing as foreign advisers and redirected victims to attacker-controlled credential-harvesting pages.
AhnLab ASEC reported that in April 2025 Kimsuky conducted a campaign dubbed Larva-24005 that exploited BlueKeep (CVE-2019-0708) and Microsoft Office Equation Editor (CVE-2017-11882). The activity was followed by deployment of MySpy, RDPWrap, and keyloggers including KimaLogger or RandomQuery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcerescana.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.