North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware

2026-05-07T02:52:00Zbf7597ae57602bf3acf5455679efb5a3afddb34e57f2e3064e5ff08a6ab0b7c0
android malwareapt37birdcallci fortifycisacritical infrastructurecve-2026-0300daemon toolsfirewall vulnerabilityftcgeolocation datakochavapalo altoprivacysqgamesupply-chain attack

What happened

Multiple security incidents: ESET attributes an Android backdoor campaign called “BirdCall” to North Korean APT37 that targeted ethnic Koreans in China via a card-game suite from Sqgame. Palo Alto Networks warned of a critical firewall vulnerability tracked as CVE-2026-0300 with patches planned in upcoming releases. Kaspersky reported a supply-chain compromise of Daemon Tools installers distributed from the official site. CISA announced “CI Fortify,” an initiative to enable critical infrastructure to operate offline during cyberattacks. The FTC banned data broker Kochava from selling precise,敏

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
bf7597ae57602bf3acf5455679efb5a3afddb34e57f2e3064e5ff08a6ab0b7c0
Enrichment time
2026-05-07T02:52:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.