North Korean APT Targets Yanbian Gamers via Trojanized Platform
ID: ee3a2ebd-0178-5496-b79b-ecc1692997d2
STIX ID: report--ee3a2ebd-0178-5496-b79b-ecc1692997d2
Feed Name: Infosecurity Magazine (News)
ESET researchers attributed a supply-chain compromise of the sqgame.net regional gaming platform to ScarCruft (APT37), which trojanized Windows and Android game clients since late 2024 to deploy RokRAT and a new Android BirdCall variant (zhuagou). The backdoors harvested contacts, call/SMS logs, documents, media and keys, used cloud storage services for C2, and appear aimed at gathering intelligence on individuals in the Yanbian Korean area; malicious APKs remained available on the site at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
