Briefing

ScarCruft’s BirdCall Backdoor Targets Ethnic Koreans in China via Game Platform Supply‑Chain Attack

security
by Bill Toulas ·

Block installation of apps from sqgame.net and enforce downloads only from official marketplaces.

What to do now

Disable installation of apps from sqgame.net and enforce download only from official marketplaces.

Summary

ScarCruft, a hacking group aligned with North Korea, has carried out a sophisticated supply‑chain espionage operation against a widely used video‑game platform. By inserting a trojanized component called BirdCallto into the platform’s build pipeline, the attackers have created a backdoor that now targets ethnic Koreans living in China. The new version of BirdCallto expands beyond the Windows‑only infections of earlier iterations, allowing the malware to spread through the game platform’s supply‑chain environment and potentially reach Android devices used by the target demographic.

The backdoor is designed to exfiltrate data from compromised systems and could be employed for targeted surveillance. Security analysts warn that the attack bypasses traditional perimeter defenses, underscoring the growing threat of supply‑chain compromises. Game developers and platform operators are urged to immediately audit their build pipelines for tampering, verify the integrity of all third‑party libraries and assets, and deploy endpoint detection tools capable of spotting the BirdCallto signature. The incident also highlights the need for stricter supply‑chain security practices across the gaming industry, as malicious actors increasingly exploit trusted development environments to infiltrate end‑user devices.

While the attack’s primary focus appears to be on gathering intelligence about ethnic Koreans in China, the broader implications touch on global cyber‑espionage dynamics. The use of a state‑aligned group to conduct a targeted operation demonstrates how geopolitical objectives can be pursued through sophisticated cyber tactics. The incident serves as a stark reminder that even well‑protected platforms can become conduits for espionage if their supply chains are not rigorously secured.

Key changes

  • APT37 released an Android BirdCall variant via trojanized APKs on sqgame.net
  • The variant extracts IP geolocation, contact list, call log, SMS, device OS, kernel, rooted status, IMEI, MAC, IP, battery temperature, RAM, storage, cloud config, backdoor version, and file extensions of interest
  • It periodically takes screenshots and records audio from 7 pm to 10 pm local time
  • It plays a silent MP3 loop to prevent suspension
  • It exfiltrates files from a specified directory
  • Missing features compared to Windows: shell command execution, traffic proxying, browser data targeting, file deletion, dropping, process killing
  • Windows version can record keystrokes, take screenshots, steal clipboard, exfiltrate files, execute commands
  • The Android variant is delivered via trojanized APKs on sqgame.net

Affects

internal

Source angles · 2 perspectives

Bleeping Computer
Independent angle

ScarCruft hackers push BirdCall Android malware via game platform

Open
The Hacker News
Independent angle

ScarCruft Compromises Video Game Platform Supply Chain, Deploys BirdCallto Backdoor Targeting Ethnic Koreans in China

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting