< Back to all clusters
[TECHNOLOGY] · United States, North Korea, Germany, Switzerland · 2 sources

started · updated

Cybersecurity experts warn of rising QR code phishing attacks

Security experts are warning of a significant rise in 'quishing'—phishing attacks that utilize malicious QR codes to bypass traditional security filters. According to the ESET Threat Report for the first half of 2026, 11% of all analyzed phishing emails contained malicious QR codes.

This tactic aims to lure victims from protected desktop environments to private mobile devices, where security measures are often less effective. These attacks are described as 'MFA-resilient,' meaning they can bypass common multi-factor authentication methods. Techniques include stealing MFA tokens, initiating malicious app downloads, and manipulating Wi-Fi connections.

The FBI has highlighted the North Korean hacker group Kimsuky (also known as APT43) for using QR codes in spearphishing attacks targeting organizations in the United States. These attacks often involve device fingerprinting to steal credentials.

To mitigate risks, experts advise users to inspect QR codes for signs of tampering, such as stickers placed over original codes, and to carefully verify the URL displayed by a smartphone before opening any linked website.

Entities

APT43 · ESET · FBI · Kimsuky

Claims

What the coverage asserts, and how many sources carry each claim.

  • [○ 1 SOURCE] 11% of analyzed phishing emails contained malicious QR codes during the first half of 2026. www.ad-hoc-news.de
  • [○ 1 SOURCE] Quishing attacks can be MFA-resilient, meaning they are capable of bypassing common multi-factor authentication. www.ad-hoc-news.de
  • [○ 1 SOURCE] The FBI is monitoring the North Korean hacker group Kimsuky (APT43) for its use of QR codes in spearphishing. www.ad-hoc-news.de