:

NORTH KOREAN HACKERS DEPLOY ANDROID MALWARE VIA GAME PLATFORM

SECURITY DESK1 MIN READ
TUE, MAY 5, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

APT37, the North Korean hacker group also known as ScarCruft, has distributed an Android version of the BirdCall backdoor through a compromised video game platform in a supply-chain attack.

The malware campaign leverages a game distribution platform to deliver BirdCall, a backdoor that grants attackers remote access to infected devices. By compromising the platform itself rather than targeting users directly, the threat actors significantly expand their reach and credibility. BirdCall previously appeared as a backdoor targeting Windows systems. The Android variant maintains similar functionality, allowing attackers to execute commands, exfiltrate data, and maintain persistent access to compromised devices. APT37 is known for conducting cyberespionage operations targeting government, defense, and financial sectors across multiple countries. The group has historically used supply-chain compromises to distribute malware at scale. Security researchers recommend users verify application sources, keep Android devices updated, and monitor for suspicious permissions requested by installed apps. Organizations should review their supply-chain security practices and implement additional verification layers for third-party software distribution.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

13H AGOIndustry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

13H AGOSecurity Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

13H AGOIndustry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

13H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.