North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware
Incidents: APT37 deployed Android ‘BirdCall’ malware via compromised card games to spy on ethnic Koreans in China.
Deep Analysis and Expert Commentary
APT37’s campaign leverages a sophisticated supply-chain attack, embedding the BirdCall backdoor in Android card games distributed through Sqgame’s compromised website. The malware’s capabilities include call recording, data exfiltration, and eavesdropping, posing significant privacy risks. The attack path involves victims downloading seemingly benign games, which later receive malicious updates. This method bypasses Google Play’s security checks, increasing the likelihood of infection. The campaign’s focus on ethnic Koreans in Yanbian suggests geopolitical espionage, targeting defectors or refugees. Mitigation includes educating users on the risks of sideloading apps, implementing robust app vetting processes, and monitoring for suspicious updates. Organizations should also enhance endpoint detection and response (EDR) capabilities to identify and neutralize such threats.
Action Items
- Educate users on the risks of sideloading apps.
- Implement robust app vetting processes.
- Enhance endpoint detection and response (EDR) capabilities.
Original Article Brief Intro
The Record by Recorded Future · 2026-05-07 · Incidents: APT37 deployed Android ‘BirdCall’ malware via compromised card games to spy on ethnic Koreans in China.
Related Terms and Notes
Threat Actors
- APT37 — A North Korean hacking group linked to espionage campaigns targeting South Korea and defectors.
- BirdCall — A sophisticated Android backdoor malware used by APT37 for espionage.
Context Notes
- Android Malware
- BirdCall
- Supply-Chain Attack