ScarCruft's Supply-Chain Attack Targets Yanbian Gaming Platform with BirdCall Malware
ID: 1e85be25-9565-5ad7-8abc-a3f9af9f3d84
STIX ID: report--1e85be25-9565-5ad7-8abc-a3f9af9f3d84
Feed Name: ThreatCluster
ESET researchers reported that North Korean APT ScarCruft conducted a supply-chain attack against the Yanbian gaming platform sqgame.net, trojanizing Windows and Android components with the BirdCall backdoor (Android versions observed Oct 2024–Jun 2025; Windows variant known since 2021). The campaign targets ethnic Koreans and North Korean defectors for intelligence collection, routes C2 through cloud storage services, and malicious APKs remain available on the site despite ESET notification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
