FBI Warns of Kimsuky Actors Leverage Malicious QR Codes to Target U.S. Organizations
The Federal Bureau of Investigation (FBI) has issued a warning regarding a new spearphishing campaign conducted by the North Korean state-sponsored group Kimsuky. This campaign utilizes QR codes to compromise U.S. organizations.
The Federal Bureau of Investigation (FBI) has issued a warning regarding a new spearphishing campaign conducted by the North Korean state-sponsored group Kimsuky. This campaign utilizes QR codes to compromise U.S. organizations.
The targeted entities include think tanks, non-governmental organizations, academic institutions, and government-linked organizations with a focus on North Korea. The campaign involves "Quishing" emails that incorporate QR images to conceal malicious URLs instead of using clickable links.
The use of QR codes allows the attackers to bypass protected corporate endpoints, directing victims to less monitored mobile devices.
In these campaigns, Kimsuky operatives impersonate trusted contacts such as foreign advisors, embassy staff, or fellow researchers. The emails prompt recipients to scan a QR code to join a conference, access a "secure" drive, or respond to a policy survey.
Once scanned, the QR code redirects the user through attacker-controlled infrastructure, fingerprinting the device and then displaying a fake login page for services like Microsoft 365, Google, Okta, or VPN gateways.
The campaign involves "Quishing" emails that incorporate QR images to conceal malicious URLs instead of using clickable links.
According to recent submissions analyzed by IC3, the QR chains are designed to evade email security and multi-factor authentication (MFA) checks while covertly collecting credentials and browser session tokens.
These operations often result in full account takeover, mailbox abuse, and long-term access to cloud resources within the victim's network.
The infection pathway shows that the QR codes initially resolve to redirector domains that log attributes such as user-agent, operating system type, IP address, language, and screen size. Server-side logic determines whether to serve a mobile-optimized phishing page or redirect the user away if the profile resembles a scanner or sandbox.
Upon landing on the fake page, victims enter their credentials, which are then harvested along with any session cookies associated with the login process. By replaying these tokens, the attackers can bypass MFA and modify access rules, forwarders, and application passwords within the account.
Subsequently, they send new QR-based phishing lures from the compromised mailbox, enhancing the credibility of the attack and maintaining access over extended periods.
Based on reporting by Cyber Security News.
