ScarCruft hackers push BirdCall Android malware via game platform
ID: fb3ad3ce-d265-5dda-89a0-0fb7f4817c76
STIX ID: report--fb3ad3ce-d265-5dda-89a0-0fb7f4817c76
Feed Name: Bleeping Computer
Threat Score
APT37 (ScarCruft) has developed and deployed an Android variant of the BirdCall backdoor by trojanizing game APKs on sqgame.net in a supply-chain campaign targeting users in the Yanbian region; ESET observed at least seven Android versions that collect contacts, SMS, device identifiers, take screenshots, record audio during evening hours, exfiltrate files, and use persistence/stealth techniques, while the Windows BirdCall retains additional remote commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
