ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows
ID: bb1e8f46-e985-52b3-a750-83a1b9589d71
STIX ID: report--bb1e8f46-e985-52b3-a750-83a1b9589d71
Feed Name: The Hacker News
ScarCruft (North Korea-aligned) conducted a supply-chain espionage campaign against the sqgame.net gaming platform used by ethnic Koreans in the Yanbian region, trojanizing Android APKs (sqgame.com.cn/ybht.apk and sqgame.com.cn/sqybhs.apk) and a Windows update DLL with a backdoor family called BirdCall. The multi-platform backdoor—an evolution of RokRAT—provides extensive surveillance (screenshots, keylogging, contacts/SMS/call logs, media, documents, ambient audio) and uses legitimate cloud services (pCloud, Yandex Disk, Zoho WorkDrive, Dropbox) for C2; the activity is assessed to have been ongoing since late 2024 and specifically targets defectors, activists, and ethnic Koreans in China.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
