Full Breakdown
FBI Warns of North Korean 'Quishing' Attacks Using Malicious QR Codes
1/9/2026, 11:51:09 PM
Overview of Quishing Tactics
The U.S. Federal Bureau of Investigation (FBI) has issued a warning regarding a series of spear-phishing campaigns conducted by the North Korean hacking group Kimsuky, also known as APT43, Black Banshee, and Velvet Chollima. These campaigns utilize malicious Quick Response (QR) codes, a tactic termed "quishing," to target think tanks, academic institutions, and government entities both in the U.S. and abroad. The FBI's advisory highlights that these QR codes are embedded in phishing emails, compelling victims to transition from secure corporate devices to potentially less secure mobile devices, thereby bypassing traditional email security measures.
Specific Incidents and Techniques
The FBI identified several incidents from May and June 2025 where Kimsuky employed quishing tactics. In one instance, an email spoofing a foreign advisor requested insights from a think tank leader regarding developments on the Korean Peninsula, including a QR code that led to a questionnaire. Another email, masquerading as an embassy employee, solicited input on North Korean human rights issues and contained a QR code claiming to provide access to a secure drive. Additionally, a strategic advisory firm received an invitation to a fictitious conference, which included a QR code redirecting them to a fake Google login page designed to harvest credentials.
Mechanism of Attack
Quishing attacks typically deliver QR codes as email attachments or embedded graphics, evading URL inspection and sandboxing. Once scanned, these codes redirect victims to attacker-controlled domains that collect device information, including IP address, operating system, and locale. This data enables attackers to present mobile-optimized phishing pages that impersonate legitimate services such as Microsoft 365 and Okta. The FBI noted that these attacks often culminate in session token theft, allowing attackers to bypass multi-factor authentication (MFA) and hijack cloud identities without triggering typical alerts.
Official Statements & Recommendations
The FBI has classified quishing as a high-confidence, MFA-resilient identity intrusion vector in enterprise environments. To combat this threat, the FBI recommends that organizations adopt a multi-layered security strategy. This includes educating employees about the risks associated with scanning unsolicited QR codes, implementing mobile device management solutions, and requiring phishing-resistant MFA for remote access. Organizations are also encouraged to establish clear reporting processes for suspicious QR codes and conduct regular audits of account permissions.
Criticism & Opposition
While the FBI's advisory emphasizes the risks posed by Kimsuky and similar groups, some cybersecurity experts argue that the focus on QR codes may divert attention from other significant threats. They caution that while quishing is a growing concern, organizations must maintain vigilance against a broader spectrum of cyber threats.
Verbatim Quotes
- “Quishing operations frequently end with session token theft and replay, enabling attackers to bypass multi-factor authentication and hijack cloud identities without triggering typical 'MFA failed' alerts,” — FBI
- “Because the compromise path originates on unmanaged mobile devices outside normal Endpoint Detection and Response (EDR) and network inspection boundaries, Quishing is now considered a high-confidence, MFA-resilient identity intrusion vector in enterprise environments.” — FBI
Conclusion
The FBI's warning underscores the evolving tactics of state-sponsored cyber threats, particularly from North Korea's Kimsuky group. As QR codes become increasingly prevalent in digital interactions, the potential for misuse in phishing attacks necessitates heightened awareness and robust security measures among organizations and individuals alike.
