BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ScarCruft Hacks Game Platform in Espionage Attack

ScarCruft group hacks video game platform to deploy BirdCall backdoor, targeting ethnic Koreans for espionage.

  • The North Korean ScarCruft hacking group compromised a video game platform to deploy the BirdCall backdoor, targeting ethnic Koreans.
  • This supply chain attack, ongoing since late 2024, marks a shift for the group by enabling multi-platform espionage against both Windows and Android users.
  • The infected platform, sqgame[.]net, is used in a border region of China that serves as a transit point for North Korean defectors.
  • BirdCall provides extensive surveillance capabilities, including screenshot capture, data theft, and audio recording.

The North Korean state-sponsored hacking group ScarCruft has been implicated in a long-running cyber espionage campaign, compromising a gaming platform since late 2024 to target ethnic Koreans in China. According to a report from ESET shared with The Hacker News, the attackers trojanized the platform’s components with a backdoor called BirdCall.

- Advertisement -

This supply chain attack represents a strategic evolution for the threat actors. Consequently, it enabled them to expand beyond their usual Windows focus and target Android devices for the first time in this operation.

The compromised platform, sqgame[.]net, hosts games for the Yanbian region bordering North Korea. “In the attack, probably ongoing since late 2024, ScarCruft compromised Windows and Android components of a video game platform dedicated to Yanbian-themed games,” the Slovakian cybersecurity company said.

Previous versions of the malware, an evolution of RokRAT, have been detected since 2021. The BirdCall backdoor itself provides capabilities for screenshot capture, keystroke logging, and data exfiltration.

For command-and-control communications, the malware leverages legitimate cloud services like Dropbox and pCloud. The Android variant specifically collects contact lists, SMS messages, call logs, and ambient audio.

- Advertisement -

Evidence suggests the Windows desktop client update package delivered a malicious DLL starting in November 2024. However, that specific package is no longer serving the trojanized component.

The Android attack specifically poisoned the download pages for two games on the platform. These pages were altered to serve malicious APKs containing the surveillance backdoor.

“The Android backdoor has seen active development, and provides surveillance capabilities, such as collection of personal data and documents, taking screenshots, and making voice recordings,” ESET concluded. The campaign aligns with ScarCruft’s known focus on North Korean defectors and activists.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Crypto PACs Pour Millions into Texas Runoff Races

Two Texas congressional runoff elections this week are being heavily influenced by spending from...

Grayscale Names ETH, SOL, BNB, CC to Benefit from Act

Grayscale has identified four cryptocurrencies—Ethereum, Solana, BNB, and Canton—as the top beneficiaries of the...

Vitalik Buterin: Ethereum Foundation to “Shrink” as Top Exodus

Ethereum Foundation co-founder Vitalik Buterin announced the organization is shrinking to focus on core...

Bitcoin Risks $72K as Sell Pressure Mounts

Bitcoin faces a potential 7% drop toward $72,000 as bearish momentum strengthens on higher...

Ghost CMS Flaw Fuels Widespread ClickFix Malware

A critical SQL injection flaw (CVE-2026-26980) in Ghost CMS is being actively exploited to...

Must Read

Are Cryptocurrency Securities?

TL;DR - Cryptocurrencies are not typically considered securities, as they are decentralized digital assets that operate independently of any central authority or government. However,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading