ScarCruft APT Compromises Yanbian Gaming Platform to Deploy Android BirdCall Spyware (welivesecurity.com)
0xBASE INTEL BRIEF
- ScarCruft compromises sqgame[.]net, a Yanbian gaming platform
- Trojanized game installers for Windows and Android distributed
- BirdCall spyware on Android targets defectors and activists
"North Korean threat actor ScarCruft (APT37) compromised the sqgame[.]net gaming platform to distribute trojanized Windows and Android games. The Android payload installs BirdCall spyware, targeting defectors and activists in China's Yanbian region. This campaign demonstrates North Korea's persistent espionage capabilities using multi-platform malware."
no comments yet.