logo

North Korean APT Targets Yanbian Gamers via Trojanized Platform

ID: ee3a2ebd-0178-5496-b79b-ecc1692997d2

STIX ID: report--ee3a2ebd-0178-5496-b79b-ecc1692997d2

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

...
...

ESET researchers attributed a supply-chain compromise of the sqgame.net regional gaming platform to ScarCruft (APT37), which trojanized Windows and Android game clients since late 2024 to deploy RokRAT and a new Android BirdCall variant (zhuagou). The backdoors harvested contacts, call/SMS logs, documents, media and keys, used cloud storage services for C2, and appear aimed at gathering intelligence on individuals in the Yanbian Korean area; malicious APKs remained available on the site at publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.