The FBI has issued a warning that North Korean state-sponsored threat actor Kimsuky is actively targeting government agencies, academic institutions, and think tanks using spear-phishing emails that contain malicious QR codes. This technique, known as “quishing,” bypasses traditional email security by embedding QR codes instead of clickable URLs, forcing victims to use unmanaged mobile devices.
Once scanned, the QR codes redirect victims through attacker-controlled domains that collect device and location data before serving mobile-optimized phishing pages impersonating Microsoft 365, Okta, or VPN login portals. By stealing session cookies, attackers can bypass MFA and hijack cloud identities. Because the initial compromise occurs outside standard EDR and network visibility, the FBI now considers quishing a high-confidence, MFA-resilient identity intrusion vector. Kimsuky has used this approach in recent espionage campaigns and has been active since at least 2012.
Chris Pierson, Founder and CEO, BlackCloak had this to say:
“Quishing is a reminder that attackers are deliberately shifting the point of compromise away from corporate infrastructure and onto personal, unmanaged devices where security controls are weakest. When executives or staff scan a QR code on their phone, they are often stepping completely outside the organization’s detection and response capabilities. That makes identity theft and session hijacking far more likely, even in environments with MFA enabled. Organizations need to treat mobile devices and digital behavior as part of the attack surface, not an edge case. Executive protection strategies must account for how attackers blend convenience, trust, and mobile workflows to bypass traditional defenses.”
Will Baxter, Field CISO, Team Cymru follows with this:
“Kimsuky’s use of quishing highlights a broader shift among nation-state actors toward identity-centric intrusion rather than malware-heavy attack chains. QR-based phishing evades traditional email controls while allowing attackers to profile the victim’s device and environment before delivering tailored lures. When session cookies or cloud tokens are stolen, MFA can be bypassed entirely, turning identities into reusable assets for follow-on espionage. This is why defenders need visibility beyond the network edge—correlating external threat intelligence with identity telemetry to spot infrastructure reuse and disrupt these campaigns earlier in the kill chain.”
If you want to learn more about Quishing and how to protect yourself, this link from Cloudflare can help you. This is handy information as this is clearly a popular means of attack from threat actors.
The North Korea Hiring Problem
Posted in Commentary with tags North Korea on August 13, 2026 by itnerdNorth Korean IT workers infiltrating US companies and government agencies points at a threat model most security teams still aren’t built for: the attacker doesn’t break in, they get hired. Once someone clears interviews and onboarding, they inherit the same trust as any other employee, and almost nobody re-verifies that trust after week one.
The State Department put out (yet another) warning about this here: Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers – United States Department of State
In the warning there’s this:
Companies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures (strict review of identification documents, requirement of in-person interviews, etc.) and detecting suspicious accounts (introduction of systems that notify anomalous information entries, etc.).
Justin Beals, CEO & Founder, Strike Graph, an AI-native GRC and compliance automation platform had this to say:
“This isn’t a hacking story. It’s a hiring failure with a nation-state attached. North Korean IT workers are getting through interviews, background checks, and onboarding because most companies still treat identity verification as a one-time gate instead of continuous evidence. Once that person is on payroll, they inherit the same trust as every other employee, and almost nobody re-checks that trust after day one.
The real gap is systemic. Organizations verify a document once, verify a face on a video call once, and then assume the risk is closed. It isn’t. Identity is not static and access should not be either. A hire that looked clean in week one can still be sitting on infrastructure tied to a sanctioned state a year later, and nobody is watching for it because nobody built a control for it.
The fix isn’t a smarter background check vendor. It’s treating high-access hiring as a compliance surface with ongoing evidence, not a one-time HR checkbox. Location consistency, device behavior, and access patterns need to be monitored the same way you’d monitor a production system, because at this point, that new hire effectively is one.”
North Koreans are here today and it is time to kick them out today. Because if they are still present tomorrow, it is one day too many.
Leave a comment »