North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware

2026-05-07T08:51:58Z05eccbff95d053dc2b32cab9829abd4972131ece4a740d047bfc2f252087bf0e
APT37Android malwareBirdCallCI FortifyCISACVE-2026-0300Daemon ToolsESETFTCKasperskyKochavaPalo Alto NetworksSqgamecritical infrastructuredata brokerexploitationfirewallgeolocationlocation dataoffline resiliencepolicyprivacysupply-chain

What happened

A roundup of security and privacy incidents: ESET links an Android backdoor called ‘BirdCall’ to North Korea’s APT37, delivered via a suite of card games from Sqgame and targeting ethnic Koreans in China; Palo Alto Networks warned of a critical firewall software bug tracked as CVE-2026-0300 that is being used in attacks and will be patched in upcoming releases; Kaspersky reported a supply-chain compromise where installers for Daemon Tools were tampered with and served from the official site; CISA launched the CI Fortify initiative to enable critical infrastructure to operate offline during/rec

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
05eccbff95d053dc2b32cab9829abd4972131ece4a740d047bfc2f252087bf0e
Enrichment time
2026-05-07T08:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.