logo

ScarCruft Targets Gaming Platform With Windows, Android Backdoors

ID: 9bc0341a-570b-5ba1-96c3-d01292cfd54a

STIX ID: report--9bc0341a-570b-5ba1-96c3-d01292cfd54a

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Mayura Kathir

...
...

ScarCruft (APT37) carried out a sophisticated supply-chain campaign by compromising sqgame.net to distribute trojanized Windows and Android games containing the BirdCall backdoor; the malware harvests contacts, messages, call logs, documents (including .hwp and .p12), media, captures screenshots and audio, and uses legitimate cloud storage services for C2, targeting ethnic Koreans in China’s Yanbian region (refugees, defectors, and persons of interest).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.