New ScarCruft Supply Chain Attack Hits Gaming Platform With Windows and Android Backdoors
ID: 6e1cbd71-acd5-5d14-ae4b-96a889448a8c
STIX ID: report--6e1cbd71-acd5-5d14-ae4b-96a889448a8c
Feed Name: cybersecurityNews.com
Threat Score
ScarCruft (aka APT37) conducted a multi-platform supply-chain attack on the sqgame gaming platform serving ethnic Koreans in Yanbian, trojanizing Android APKs with the BirdCall backdoor and delivering RokRAT via a malicious Windows update to harvest sensitive personal data from refugees and defectors; ESET and WeLiveSecurity confirmed active exploitation since late 2024 and published IoCs for threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
