BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ScarCruft Hacks Game Platform in Espionage Attack

ScarCruft group hacks video game platform to deploy BirdCall backdoor, targeting ethnic Koreans for espionage.

  • The North Korean ScarCruft hacking group compromised a video game platform to deploy the BirdCall backdoor, targeting ethnic Koreans.
  • This supply chain attack, ongoing since late 2024, marks a shift for the group by enabling multi-platform espionage against both Windows and Android users.
  • The infected platform, sqgame[.]net, is used in a border region of China that serves as a transit point for North Korean defectors.
  • BirdCall provides extensive surveillance capabilities, including screenshot capture, data theft, and audio recording.

The North Korean state-sponsored hacking group ScarCruft has been implicated in a long-running cyber espionage campaign, compromising a gaming platform since late 2024 to target ethnic Koreans in China. According to a report from ESET shared with The Hacker News, the attackers trojanized the platform’s components with a backdoor called BirdCall.

- Advertisement -

This supply chain attack represents a strategic evolution for the threat actors. Consequently, it enabled them to expand beyond their usual Windows focus and target Android devices for the first time in this operation.

The compromised platform, sqgame[.]net, hosts games for the Yanbian region bordering North Korea. “In the attack, probably ongoing since late 2024, ScarCruft compromised Windows and Android components of a video game platform dedicated to Yanbian-themed games,” the Slovakian cybersecurity company said.

Previous versions of the malware, an evolution of RokRAT, have been detected since 2021. The BirdCall backdoor itself provides capabilities for screenshot capture, keystroke logging, and data exfiltration.

For command-and-control communications, the malware leverages legitimate cloud services like Dropbox and pCloud. The Android variant specifically collects contact lists, SMS messages, call logs, and ambient audio.

- Advertisement -

Evidence suggests the Windows desktop client update package delivered a malicious DLL starting in November 2024. However, that specific package is no longer serving the trojanized component.

The Android attack specifically poisoned the download pages for two games on the platform. These pages were altered to serve malicious APKs containing the surveillance backdoor.

“The Android backdoor has seen active development, and provides surveillance capabilities, such as collection of personal data and documents, taking screenshots, and making voice recordings,” ESET concluded. The campaign aligns with ScarCruft’s known focus on North Korean defectors and activists.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ras Al Khaimah free zone launches first onchain business IDs

Innovation City in Ras Al Khaimah has launched the first blockchain-based digital business identity...

Couple’s Parking Lot Burrito Shed Nets $2.3M

A California couple generated $2.3 million in sales from a burrito cafe they launched...

ARK Buys Shopify Ahead of Earnings, AI Focus

Ark Invest purchased over $9.2 million worth of Shopify shares ahead of its Q1...

Aave moves to block law firm’s freeze of Kelp DAO exploit funds

DeFi giant Aave filed an emergency motion on Monday in a New York court...

Theta Labs Adds Alibaba Cloud, Expands AI to Twitch in April

Theta EdgeCloud now offers developers a 5% rebate in TDROP tokens on all GPU...

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading