FBI Warns of North Korean Hackers Using QR Codes to Target U.S. Policy Groups
The FBI has issued a 2025 FLASH alert to NGOs, think tanks, universities, and government-affiliated organizations, warning of North Korean hacking group Kimsuky APT's use of QR codes in spearphishing campaigns. Dubbed 'Quishing,' this method bypasses traditional email security measures by embedding malicious URLs in QR codes, which victims typically scan with personal devices rather than monitored work computers.
Kimsuky APT has tailored its attacks to the interests of its targets, sending themed emails with QR codes that purport to LINK to questionnaires, secure drives, or other relevant content. In May 2025, the group impersonated a foreign advisor and an embassy worker, while in June, it targeted a strategic advisory firm. The FBI emphasizes that all victims share a focus on North Korea-related research or policy.