North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware

2026-05-06T02:51:58Z7b62aadce77373323f4772b011626b3903fc8a1925f19b19d49af00e61628ab4
AIAPT37AkiraAndroid malwareAustraliaBirdCallContiCyber Incident Review BoardFTCGermanyKochavaSqgamecyber policydata brokerfacial recognitiongeolocationmobile malwareprivacyransomwaresentencingsurveillance

What happened

Multiple cybersecurity and policy developments: ESET attributes an Android backdoor campaign called “BirdCall” to North Korean APT37, which distributed a backdoor bundled with card games from Sqgame to target ethnic Koreans in China. The U.S. FTC barred data broker Kochava from selling precise geolocation data tied to sensitive locations (houses of worship, clinics). Deniss Zolotarjovs, an affiliate of Conti/Akira ransomware, received an 8-year sentence for money laundering and wire fraud. Australia launched a Cyber Incident Review Board for no‑fault post‑incident reviews, and German officials

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
7b62aadce77373323f4772b011626b3903fc8a1925f19b19d49af00e61628ab4
Enrichment time
2026-05-06T02:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.