logo

ScarCruft's Supply-Chain Attack Targets Yanbian Gaming Platform with BirdCall Malware

ID: 1e85be25-9565-5ad7-8abc-a3f9af9f3d84

STIX ID: report--1e85be25-9565-5ad7-8abc-a3f9af9f3d84

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

...
...

ESET researchers reported that North Korean APT ScarCruft conducted a supply-chain attack against the Yanbian gaming platform sqgame.net, trojanizing Windows and Android components with the BirdCall backdoor (Android versions observed Oct 2024–Jun 2025; Windows variant known since 2021). The campaign targets ethnic Koreans and North Korean defectors for intelligence collection, routes C2 through cloud storage services, and malicious APKs remain available on the site despite ESET notification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.