Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ScarCruft Exploits Gaming Platform with Backdoor Attacks

ScarCruft Exploits Gaming Platform with Backdoor Attacks

Posted on May 5, 2026 By CWS

A cyber espionage group linked to North Korea, known as ScarCruft, has been identified executing a supply chain attack on a gaming platform catering to ethnic Koreans in China’s Yanbian region. This malicious operation involved embedding backdoors into both Windows and Android versions of the platform’s games, effectively transforming a reliable service into a tool for covert surveillance.

ScarCruft’s Strategic Targeting

The attack, which has likely been ongoing since late 2024, appears to be aimed at gathering sensitive information on individuals of interest to the North Korean government, such as refugees and defectors. The compromised platform, named sqgame, offers card and board games themed around the Yanbian region for Windows, Android, and iOS users. ScarCruft did not penetrate the game’s source code directly; instead, they accessed the platform’s web server and altered the original Android game files with harmful code.

Two Android games from the sqgame website were infected with the BirdCall backdoor, while the Windows client was attacked using a malicious update package. The iOS version seemed unaffected, likely due to Apple’s stringent review process that adds a layer of difficulty in targeting.

Analysis by Security Experts

WeLiveSecurity analysts, attributing the attack to ScarCruft with high confidence, revealed a comprehensive analysis of this multi-platform supply chain threat. Their investigation highlighted the new Android BirdCall tool within ScarCruft’s arsenal, marking the first public review of this variant. ESET telemetry confirmed the malicious Windows update has been active since at least November 2024, initially deploying the RokRAT backdoor before introducing the more sophisticated BirdCall backdoor onto victim systems.

ScarCruft, also known as APT37 or Reaper, has been operational since at least 2012, often identified as a North Korean state-sponsored cyber espionage entity. While their primary targets are in South Korea, they have also attacked other Asian nations, focusing on government, military, and industry sectors linked to North Korean interests. The Yanbian region, bordering North Korea and hosting the largest ethnic Korean community outside the peninsula, aligns closely with the group’s targeting strategy, particularly as a potential crossing point for defectors.

Implications and Precautions

The Android BirdCall backdoor, internally named “zhuagou,” is spread through altered game packages hosted on the sqgame website. Each APK’s AndroidManifest.xml file is modified to reroute the app’s startup to the backdoor’s code. As users engage with the game, the backdoor discreetly operates in the background, making the infection undetectable.

Upon initial execution, the backdoor compiles a directory listing of shared storage and captures user contacts, call logs, and SMS messages. It connects to cloud storage with embedded credentials, uploading data such as RAM, IMEI, IP and MAC addresses, and geolocation information. Communication occurs via HTTPS using Zoho WorkDrive accounts, with researchers discovering 12 distinct drives utilized in the campaign. In some variants, audio recording is enabled between 7 PM and 10 PM local time. The backdoor also takes screenshots and extracts files with extensions like .jpg, .doc, .pdf, .xls, .xlsx, .ppt, .pptx, .txt, .hwp, .m4a, and .p12.

On Windows systems, ScarCruft integrated a trojanized mono.dll into an sqgame update package. A downloader within the library checks for analysis tools and virtual environments before retrieving shellcode from a compromised South Korean website containing RokRAT. Following the payload drop, it replaces itself with a clean version to eliminate traces. RokRAT then installs the complete BirdCall backdoor on the compromised machine.

Individuals are advised to install applications solely from trusted sources like Google Play and ensure devices are consistently updated. Security teams should monitor unexpected HTTPS traffic to cloud platforms from gaming applications. A comprehensive list of Indicators of Compromise is available in the ESET GitHub repository for threat hunting.

Stay informed by following us on Google News, LinkedIn, and X. Set us as a preferred source on Google for more immediate updates.

Cyber Security News Tags:Android, APT37, Backdoor, BirdCall, cyber espionage, Cybersecurity, digital security, ESET, gaming platform, North Korea, RokRAT, ScarCruft, supply chain attack, Windows, Yanbian

Post navigation

Previous Post: Critical Vulnerabilities in Qualcomm Chipsets Risk Remote Exploits
Next Post: China-Linked Group Targets Exchange Servers with Malware

Related Posts

Microsoft, Cisco, Fortinet Security Updates and Cyber Attacks Microsoft, Cisco, Fortinet Security Updates and Cyber Attacks Cyber Security News
Microsoft Teams to Introduce External Domains Anomalies Report for Enhanced Security Microsoft Teams to Introduce External Domains Anomalies Report for Enhanced Security Cyber Security News
Everest Hacking Group Allegedly Claims Breach of Nissan Motors Everest Hacking Group Allegedly Claims Breach of Nissan Motors Cyber Security News
Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack Cyber Security News
Threat Actors Targeting Ukraine’s Defense Forces With Charity-Themed Malware Campaign Threat Actors Targeting Ukraine’s Defense Forces With Charity-Themed Malware Campaign Cyber Security News
UNC2891 Threat Actors Hacked ATM Networks Using 4G Raspberry Pi Device UNC2891 Threat Actors Hacked ATM Networks Using 4G Raspberry Pi Device Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework
  • Rust-Based Ransomware Threatens Global Industries
  • Unpatchable usbliter8 Exploit Affects Apple Devices
  • Critical Flaw in Avada Plugin Threatens 1 Million Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework
  • Rust-Based Ransomware Threatens Global Industries
  • Unpatchable usbliter8 Exploit Affects Apple Devices
  • Critical Flaw in Avada Plugin Threatens 1 Million Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark