ScarCruft’s BirdCall Backdoor Targets Ethnic Koreans in China via Game Platform Supply‑Chain Attack
Block installation of apps from sqgame.net and enforce downloads only from official marketplaces.
Disable installation of apps from sqgame.net and enforce download only from official marketplaces.
Summary
ScarCruft, a hacking group aligned with North Korea, has carried out a sophisticated supply‑chain espionage operation against a widely used video‑game platform. By inserting a trojanized component called BirdCallto into the platform’s build pipeline, the attackers have created a backdoor that now targets ethnic Koreans living in China. The new version of BirdCallto expands beyond the Windows‑only infections of earlier iterations, allowing the malware to spread through the game platform’s supply‑chain environment and potentially reach Android devices used by the target demographic.
The backdoor is designed to exfiltrate data from compromised systems and could be employed for targeted surveillance. Security analysts warn that the attack bypasses traditional perimeter defenses, underscoring the growing threat of supply‑chain compromises. Game developers and platform operators are urged to immediately audit their build pipelines for tampering, verify the integrity of all third‑party libraries and assets, and deploy endpoint detection tools capable of spotting the BirdCallto signature. The incident also highlights the need for stricter supply‑chain security practices across the gaming industry, as malicious actors increasingly exploit trusted development environments to infiltrate end‑user devices.
While the attack’s primary focus appears to be on gathering intelligence about ethnic Koreans in China, the broader implications touch on global cyber‑espionage dynamics. The use of a state‑aligned group to conduct a targeted operation demonstrates how geopolitical objectives can be pursued through sophisticated cyber tactics. The incident serves as a stark reminder that even well‑protected platforms can become conduits for espionage if their supply chains are not rigorously secured.
Key changes
- APT37 released an Android BirdCall variant via trojanized APKs on sqgame.net
- The variant extracts IP geolocation, contact list, call log, SMS, device OS, kernel, rooted status, IMEI, MAC, IP, battery temperature, RAM, storage, cloud config, backdoor version, and file extensions of interest
- It periodically takes screenshots and records audio from 7 pm to 10 pm local time
- It plays a silent MP3 loop to prevent suspension
- It exfiltrates files from a specified directory
- Missing features compared to Windows: shell command execution, traffic proxying, browser data targeting, file deletion, dropping, process killing
- Windows version can record keystrokes, take screenshots, steal clipboard, exfiltrate files, execute commands
- The Android variant is delivered via trojanized APKs on sqgame.net