North Korea turns QR codes into phishing weapons
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
North Korean state-backed hackers are using QR codes embedded in spear phishing emails to steal credentials and bypass multi-factor authentication. The Kimsuky group targets thinktanks, academic institutions, and government organizations by redirecting victims who scan QR codes to fake Microsoft 365, Okta, or VPN login portals. This "quishing" technique is particularly effective because traditional security tools cannot inspect QR code graphics, and victims typically scan them on unmanaged mobile devices. The FBI recommends implementing controls to inspect QR links and treating mobile phones as managed endpoints.
Sort: