:

NORTH KOREAN HACKERS DEPLOY ANDROID MALWARE VIA GAME PLATFORM

SECURITY DESK1 MIN READ
TUE, MAY 5, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

APT37, the North Korean hacker group also known as ScarCruft, has distributed an Android version of the BirdCall backdoor through a compromised video game platform in a supply-chain attack.

The malware campaign leverages a game distribution platform to deliver BirdCall, a backdoor that grants attackers remote access to infected devices. By compromising the platform itself rather than targeting users directly, the threat actors significantly expand their reach and credibility. BirdCall previously appeared as a backdoor targeting Windows systems. The Android variant maintains similar functionality, allowing attackers to execute commands, exfiltrate data, and maintain persistent access to compromised devices. APT37 is known for conducting cyberespionage operations targeting government, defense, and financial sectors across multiple countries. The group has historically used supply-chain compromises to distribute malware at scale. Security researchers recommend users verify application sources, keep Android devices updated, and monitor for suspicious permissions requested by installed apps. Organizations should review their supply-chain security practices and implement additional verification layers for third-party software distribution.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cody Wilson, creator of the first 3D-printed gun, says he's developed software to bypass government-mandated blocks on 3D printers making firearms. The claim marks the start of an escalating regulatory battle over ghost guns.

JUST NOWIndustry Desk

Hackers are exploiting critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The flaws allow attackers to forge SAML responses and gain administrator access.

JUST NOWSecurity Desk

Microsoft's Paint and Photos applications automatically embed invisible GUIDs into locally generated images, according to reverse engineering analysis. The watermarks persist even when files are created entirely offline.

1H AGOAI Desk

Chinese threat actors are integrating DeepSeek and other open-source AI models into cyberattacks, researchers report. The shift demonstrates how readily available AI tools can amplify hacking capabilities against international targets.

2H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.