logo

North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware

ID: 49976853-bd48-5e5d-963a-419c3ee2453e

STIX ID: report--49976853-bd48-5e5d-963a-419c3ee2453e

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2026-05-07

Date Updated: 2026-05-11

...
...

ESET researchers attribute a supply-chain campaign to North Korean APT37 that delivered the BirdCall backdoor via compromised Sqgame card games; BirdCall (Windows and Android variants) can take screenshots, record audio/calls, and exfiltrate contacts, SMS, call logs, media files and private keys. Victims (targeted ethnic Koreans in Yanbian and likely North Korean defectors) downloaded the compromised apps directly from the web, and the malicious update package was active since at least November 2024 before being remediated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.