logo

ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows

ID: bb1e8f46-e985-52b3-a750-83a1b9589d71

STIX ID: report--bb1e8f46-e985-52b3-a750-83a1b9589d71

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

ScarCruft (North Korea-aligned) conducted a supply-chain espionage campaign against the sqgame.net gaming platform used by ethnic Koreans in the Yanbian region, trojanizing Android APKs (sqgame.com.cn/ybht.apk and sqgame.com.cn/sqybhs.apk) and a Windows update DLL with a backdoor family called BirdCall. The multi-platform backdoor—an evolution of RokRAT—provides extensive surveillance (screenshots, keylogging, contacts/SMS/call logs, media, documents, ambient audio) and uses legitimate cloud services (pCloud, Yandex Disk, Zoho WorkDrive, Dropbox) for C2; the activity is assessed to have been ongoing since late 2024 and specifically targets defectors, activists, and ethnic Koreans in China.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.