Kimsuki is a apt_group tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 8, 2026; most recent activity January 8, 2026.
Kimsuky is a North Korea–linked APT group known for cyber-espionage campaigns targeting government, think tanks, and other organizations. A recent FBI warning indicates the group is increasingly using QR codes as phishing lures to target U.S. organizations, signaling a shift toward QR-based social engineering and ongoing credential/malware delivery campaigns.
The FBI has issued a warning about the North Korean hacker group Kimsuky employing malicious QR codes in spear-phishing campaigns targeting U.S. organizations. The attacks focus on entities involved in North…