logo

ScarCruft Supply Chain Attack Targets Gaming Platform Users

ID: 01117dcc-9ee1-5aa3-984d-fd42fa7b753d

STIX ID: report--01117dcc-9ee1-5aa3-984d-fd42fa7b753d

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Varshini

...
...

ScarCruft (APT37) conducted a late-2024 supply-chain campaign targeting ethnic Koreans in China’s Yanbian region by trojanizing Windows and Android versions of local card/board games to deliver BirdCall, a sophisticated backdoor/spyware. The Windows chain uses a malicious mono.dll and RokRAT downloader to install BirdCall and then attempts to cover tracks; the Android variant steals contacts, SMS/call logs, documents and media, captures screenshots, and records ambient audio on a scheduled window. Both variants use legitimate cloud storage services (Dropbox, pCloud, Zoho WorkDrive, Yandex Disk) for command-and-control and exfiltration, increasing stealth and complicating detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.