FBI warns Kimsuky used malicious QR codes in 2025 quishing campaigns

by

A flash alert from the FBI warned that North Korean state sponsored threat group Kimsuky used malicious QR codes in spear phishing campaigns in 2025 targeting think tanks, academic institutions, and U.S. and foreign government entities.

KEY FACTS

  • Threat actor Kimsuky, also tracked as APT43
  • Technique malicious QR codes used in spear phishing, known as quishing
  • Targets think tanks, academic institutions, U.S. and foreign government entities
  • Impact session token theft and multi factor authentication bypass risk

Observed activity in May and June 2025 included spoofed emails that used QR codes to direct recipients to questionnaires, a claimed secure drive, attacker controlled infrastructure, and a fake registration page designed to harvest Google account credentials.

Quishing moves victims from enterprise protected machines to mobile devices that often lack endpoint detection and response and network inspection controls. That shift can allow attackers to bypass traditional defenses.

These operations frequently ended with session token theft and replay, enabling attackers to bypass multi factor authentication and hijack cloud identities without triggering typical MFA failed alerts.

Compromised mailboxes were used to establish persistence and to send follow on spear phishing. The overall number of successful intrusions and the full scope of impact were not specified.

WHY IT MATTERS

QR code phishing transfers access control to unmanaged mobile devices and can bypass both endpoint and identity controls. The tactic presents a high confidence, MFA resilient identity intrusion vector for affected organizations.