ATT&CKReferencesEnkiWhiteHat_KimsukyDOCSWAP_Dec2025

EnkiWhiteHat_KimsukyDOCSWAP_Dec2025

EnkiWhiteHat. (2025, December 16). Kimsuky Distributing Malicious Mobile App via QR Code. Retrieved January 8, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
GroupKimsuky

Kimsuky has renamed malware to legitimate names such as ESTCommon.dll or patch.dll. Kimsuky has also disguised payloads using legitimate file names including a PowerShell payload named chrome.ps1. Kimsuky has also used a malicious QR code that masqueraded as a legitimate package delivery service.

T1598.003
Spearphishing Link
GroupKimsuky

Kimsuky has used links in e-mail to steal account information including web beacons for target profiling. Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.