ScarCruft Targets Gaming Platform With Windows, Android Backdoors
ID: 9bc0341a-570b-5ba1-96c3-d01292cfd54a
STIX ID: report--9bc0341a-570b-5ba1-96c3-d01292cfd54a
Feed Name: GBHackers
Threat Score
ScarCruft (APT37) carried out a sophisticated supply-chain campaign by compromising sqgame.net to distribute trojanized Windows and Android games containing the BirdCall backdoor; the malware harvests contacts, messages, call logs, documents (including .hwp and .p12), media, captures screenshots and audio, and uses legitimate cloud storage services for C2, targeting ethnic Koreans in China’s Yanbian region (refugees, defectors, and persons of interest).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
