Threat Management, Ransomware, Phishing, Threat Intelligence, Endpoint/Device Security, Government security

FBI: Kimsuky steals credentials via QR code ‘quishing’ attacks

Computer keyboard, close-up button of the flag of North Korea.

The FBI on Jan. 8 warned non-government organizations (NGOs), think tanks, academics, and other foreign policy experts that the North Korean threat group Kimsuky targeted them with QR Code (quishing) attacks.

According to the FBI, threat actors run these quishing attacks to get victims to scan malicious QR codes that pushes them to use their mobile devices, and then redirects them to fake websites that selectively present mobile-optimized credential harvesting pages impersonating Microsoft 365, Okta, or VPN portals.

“The FBI putting out a flash alert signals they're seeing enough activity to warrant public warning,” said Michael Bell, chief executive officer at Suzu Labs. “Kimsuky isn't going after random people, they're targeting organizations involved in North Korea policy, research, and analysis. “We’re talking think tanks, academic institutions, government entities, the people who shape how the U.S. understands and responds to North Korea.”

Bell explained that Kimsuky operates under North Korea's Reconnaissance General Bureau and has been active since at least 2012. They tend to focus on intelligence collection rather than the financial theft operations that Lazarus handles and their typical playbook is credential harvesting through spear-phishing, often impersonating journalists, researchers, or government officials.

“They build rapport before sending the payload," said Bell. "The QR code shift is a technique adaptation, not a new mission. They're still after the same targets. They've just found a delivery method that works. Our research shows them distributing Android malware called DocSwap through QR codes on fake logistics company sites. Once installed, it’s a full remote access trojan with access to messages, calls, files, cameras and microphones.”


Related reading:


Nevan Beal, principal MDR Analyst at Blackpoint Cyber, explained that quishing works because it hides the malicious link within a QR image, which can slip past email defenses that are built to inspect normal clickable URLs. Beal said it also nudges the user to scan this image with their mobile device, where security monitoring is often lighter than on a managed work laptop. On mobile, Beal said it’s harder to sanity-check the destination since the it's not possible to hover over the URL, and the full URL often gets buried or truncated.  

“Kimsuky takes advantage of this friction to steal credentials and session tokens, which often lead to account takeover even when MFA in place,” said Beal. “This threat group uses quishing because it's the lowest-effort way to slip past link-focused defenses, push targets onto less-monitored phones, and snag credentials or session tokens that translate into quiet, long-term access for espionage. All of this destruction from one totally normal little square.”

Chris Pierson, founder and CEO at BlackCloak, said quishing reminds us that attackers are deliberately shifting the point of compromise away from corporate infrastructure and onto personal, unmanaged devices where security controls are weakest. Pierson said when executives or staff scan a QR code on their phone, they are often stepping completely outside the organization’s detection and response capabilities.

“That makes identity theft and session hijacking far more likely, even in environments with MFA enabled,” said Pierson. “Organizations need to treat mobile devices and digital behavior as part of the attack surface, not an edge case. Executive protection strategies must account for how attackers blend convenience, trust, and mobile workflows to bypass traditional defenses.”



Bell from Suzu Labs added that most email security tools are trained to scan URLs, attachments, and embedded links. QR codes don't contain a visible URL in the email body. They're images, so the security filter sees an image, not a link, which means it doesn't flag the destination. The actual redirect happens when someone scans the code with their phone,s aid bell.

“That's the first bypass,” said Bell. “The second is the phone itself. When someone scans a QR code, they're probably using a personal device that doesn't have the same security stack as their work laptop. No corporate email gateway. No endpoint detection. No browser filtering. The victim just opened a phishing link on an unmanaged device and the security team has no visibility. That combination makes quishing effective even though the technique is years old. Not all security tools have caught up.”

Or Eshed, co-founder and CEO of LayerX Security, said these attacks are successful because they are cleverly designed to rely on human weakness. Whereas a phishing email will probably go through server-side email scanning and will get opened in an email client managed by the organization, Eshed said a QR code opens the link directly in the user’s browser, without passing through any traditional enterprise security tools. 

“Moreover, scanning QR codes explicitly requires us to use our mobile devices, which are typically BYOD personal devices,” said Eshed. “And while we’ve grown to distrust unknown text messages, most people don’t have the same immediate level of suspicion towards QR codes. That's why it’s critical for enterprises to secure not just the traditional attack channels of email attacks, but also protect web-based interactions, even in mobile devices.”

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds