1 of 2
Story summary
- The Federal Bureau of Investigation (FBI) warns that Kimsuky uses Quick Response (QR) codes in targeted spearphishing.
- The campaigns target U.S. think tanks, academic institutions, and government officials involved in North Korean affairs.
- Since May 2025, Kimsuky has sent emails with QR codes redirecting to fake login pages for Microsoft 365 and Okta to harvest credentials.
- The FBI urges verification of QR sources and adoption of multi-layered security measures.
1 / 2
