North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware
2026-05-07T08:51:58Z•05eccbff95d053dc2b32cab9829abd4972131ece4a740d047bfc2f252087bf0e
APT37Android malwareBirdCallCI FortifyCISACVE-2026-0300Daemon ToolsESETFTCKasperskyKochavaPalo Alto NetworksSqgamecritical infrastructuredata brokerexploitationfirewallgeolocationlocation dataoffline resiliencepolicyprivacysupply-chain
What happened
A roundup of security and privacy incidents: ESET links an Android backdoor called ‘BirdCall’ to North Korea’s APT37, delivered via a suite of card games from Sqgame and targeting ethnic Koreans in China; Palo Alto Networks warned of a critical firewall software bug tracked as CVE-2026-0300 that is being used in attacks and will be patched in upcoming releases; Kaspersky reported a supply-chain compromise where installers for Daemon Tools were tampered with and served from the official site; CISA launched the CI Fortify initiative to enable critical infrastructure to operate offline during/rec
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 05eccbff95d053dc2b32cab9829abd4972131ece4a740d047bfc2f252087bf0e
- Enrichment time
- 2026-05-07T08:51:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.