North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware
2026-05-06T02:51:58Z•7b62aadce77373323f4772b011626b3903fc8a1925f19b19d49af00e61628ab4
AIAPT37AkiraAndroid malwareAustraliaBirdCallContiCyber Incident Review BoardFTCGermanyKochavaSqgamecyber policydata brokerfacial recognitiongeolocationmobile malwareprivacyransomwaresentencingsurveillance
What happened
Multiple cybersecurity and policy developments: ESET attributes an Android backdoor campaign called “BirdCall” to North Korean APT37, which distributed a backdoor bundled with card games from Sqgame to target ethnic Koreans in China. The U.S. FTC barred data broker Kochava from selling precise geolocation data tied to sensitive locations (houses of worship, clinics). Deniss Zolotarjovs, an affiliate of Conti/Akira ransomware, received an 8-year sentence for money laundering and wire fraud. Australia launched a Cyber Incident Review Board for no‑fault post‑incident reviews, and German officials
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 7b62aadce77373323f4772b011626b3903fc8a1925f19b19d49af00e61628ab4
- Enrichment time
- 2026-05-06T02:51:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.