North Korean Hackers Hide Spyware in Mobile Games to Target Ethnic Koreans

North Korean Hackers Hide Spyware in Mobile Games to Target Ethnic Koreans

A mobile phone screenshot displaying a grid of brightly colored, animated Korean characters on a light blue background.

North Korean Hackers Hide Spyware in Mobile Games to Target Ethnic Koreans

A North Korean hacking group has been targeting ethnic Koreans in China’s Yanbian region using malicious software hidden in mobile games. The group, known as APT37, infected devices with a backdoor called BirdCall to steal personal data and spy on users. Researchers first uncovered the threat in 2021, but a new Android version has since emerged. APT37 has been active since 2012, primarily running espionage campaigns against South Korea and other Asian nations. Their latest operation focused on Yanbian, a region bordering North Korea with a large population of refugees and defectors. The attackers hid BirdCall in updates for popular Android games developed by Sqgame.

The initial game files downloaded from Sqgame’s website were harmless. The malware was introduced later through a compromised update package. Once installed, BirdCall allowed APT37 to take screenshots, record calls, and steal sensitive information. On Android devices, the malware could access contact lists, SMS messages, call logs, media files, and even private cryptographic keys. While BirdCall was first identified on Windows in 2021 by South Korean cybersecurity firm AhnLab, the discovery of an Android variant shows the group’s expanding reach. ESET researchers attempted to warn Sqgame in December 2025 but received no reply.

The attack highlights APT37’s continued focus on espionage through deceptive software. By disguising malware in game updates, the group successfully targeted vulnerable communities. Security experts warn that infected devices remain at risk of data theft and surveillance.

Neueste Nachrichten