Skip to content
NetarxImpact Database
QR Code PhishingNo AI reportedConfirmedCampaign

FBI FLASH warns of Kimsuky QR-code spear phishing on think tanks and government

Think tanks, academic institutions and government entities · Government · United States · January 8, 2026

What happened

The FBI issued a FLASH alert on 8 January 2026 warning that North Korean state-sponsored group Kimsuky, also tracked as APT43, was embedding malicious QR codes in spear-phishing emails aimed at think tanks, academics and government bodies. The FBI documented incidents from May and June 2025 in which the group spoofed foreign officials and embassy staff to solicit information from think tank leaders, and redirected targets to fake Google credential pages and bogus document-sharing sites.

How the deception worked

Kimsuky wrote emails in the voice of a diplomat or embassy employee inviting a policy expert to an event or a document review, and placed the link inside a QR code rather than as clickable text. Scanning moved the victim off the monitored corporate desktop onto a personal phone, where enterprise mail filtering and endpoint detection do not reach, and onto a spoofed Google or document-portal sign-in. The FBI noted these operations frequently end in session token theft and replay, which defeats multi-factor authentication because the attacker never faces the login challenge.

The control that would have caught it· our reading, not a claim from the sources

Treat QR codes in inbound mail as untrusted links and render them for inspection at the gateway; bind sessions to device posture so a stolen token cannot be replayed from unmanaged hardware.

Sources (2)

  1. FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing
    The Hacker News·thehackernews.comOpen ↗
  2. FBI FLASH AC-000001-MW, 08 January 2026
    FBI / IC3·ic3.govOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.