ScarCruft Supply Chain Attack Targets Gaming Platform Users
ID: 01117dcc-9ee1-5aa3-984d-fd42fa7b753d
STIX ID: report--01117dcc-9ee1-5aa3-984d-fd42fa7b753d
Feed Name: Cyber Press
ScarCruft (APT37) conducted a late-2024 supply-chain campaign targeting ethnic Koreans in China’s Yanbian region by trojanizing Windows and Android versions of local card/board games to deliver BirdCall, a sophisticated backdoor/spyware. The Windows chain uses a malicious mono.dll and RokRAT downloader to install BirdCall and then attempts to cover tracks; the Android variant steals contacts, SMS/call logs, documents and media, captures screenshots, and records ambient audio on a scheduled window. Both variants use legitimate cloud storage services (Dropbox, pCloud, Zoho WorkDrive, Yandex Disk) for command-and-control and exfiltration, increasing stealth and complicating detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
