logo

New ScarCruft Supply Chain Attack Hits Gaming Platform With Windows and Android Backdoors

ID: 6e1cbd71-acd5-5d14-ae4b-96a889448a8c

STIX ID: report--6e1cbd71-acd5-5d14-ae4b-96a889448a8c

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

ScarCruft (aka APT37) conducted a multi-platform supply-chain attack on the sqgame gaming platform serving ethnic Koreans in Yanbian, trojanizing Android APKs with the BirdCall backdoor and delivering RokRAT via a malicious Windows update to harvest sensitive personal data from refugees and defectors; ESET and WeLiveSecurity confirmed active exploitation since late 2024 and published IoCs for threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.