:

NORTH KOREAN HACKERS DEPLOY ANDROID MALWARE VIA GAME PLATFORM

SECURITY DESK1 MIN READ
TUE, MAY 5, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

APT37, the North Korean hacker group also known as ScarCruft, has distributed an Android version of the BirdCall backdoor through a compromised video game platform in a supply-chain attack.

The malware campaign leverages a game distribution platform to deliver BirdCall, a backdoor that grants attackers remote access to infected devices. By compromising the platform itself rather than targeting users directly, the threat actors significantly expand their reach and credibility. BirdCall previously appeared as a backdoor targeting Windows systems. The Android variant maintains similar functionality, allowing attackers to execute commands, exfiltrate data, and maintain persistent access to compromised devices. APT37 is known for conducting cyberespionage operations targeting government, defense, and financial sectors across multiple countries. The group has historically used supply-chain compromises to distribute malware at scale. Security researchers recommend users verify application sources, keep Android devices updated, and monitor for suspicious permissions requested by installed apps. Organizations should review their supply-chain security practices and implement additional verification layers for third-party software distribution.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.

JUST NOWSecurity Desk

A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.

JUST NOWIndustry Desk

McKesson, a major healthcare and pharmaceutical distributor, confirmed a cybersecurity incident involving unauthorized access to third-party applications. Extortion group ShinyHunters claims responsibility for stealing 284 million patient data records.

JUST NOWAI Desk

Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.

3H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.