North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware
2026-05-07T02:52:00Z•bf7597ae57602bf3acf5455679efb5a3afddb34e57f2e3064e5ff08a6ab0b7c0
android malwareapt37birdcallci fortifycisacritical infrastructurecve-2026-0300daemon toolsfirewall vulnerabilityftcgeolocation datakochavapalo altoprivacysqgamesupply-chain attack
What happened
Multiple security incidents: ESET attributes an Android backdoor campaign called “BirdCall” to North Korean APT37 that targeted ethnic Koreans in China via a card-game suite from Sqgame. Palo Alto Networks warned of a critical firewall vulnerability tracked as CVE-2026-0300 with patches planned in upcoming releases. Kaspersky reported a supply-chain compromise of Daemon Tools installers distributed from the official site. CISA announced “CI Fortify,” an initiative to enable critical infrastructure to operate offline during cyberattacks. The FTC banned data broker Kochava from selling precise,敏
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- bf7597ae57602bf3acf5455679efb5a3afddb34e57f2e3064e5ff08a6ab0b7c0
- Enrichment time
- 2026-05-07T02:52:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.