North Korean hacking group ScarCruft has compromised a gaming platform in a supply chain attack, modifying its credentials with a backdoor called BirdCall. The espionage campaign is likely targeting Koreans living in China.

This backdoor has been observed before, but previous versions mainly targeted Windows. The new attack also targets Android, making it a multi-platform threat.
According to ESET, the campaign has targeted sqgame[.]net, a gaming platform used by Koreans living in the Yanbian of China (bordering North Korea and Russia). The region is known as a major high-risk crossing point for North Korean defectors crossing the Tumen.
See also: ScarCruft spreads RokRAT malware via Windows Zero-Day
Targeting this platform is a deliberate strategy, given ScarCruft of targeting North Korean defectors, human rights activists, and university professors.
In the attack, which has likely been ongoing since late 2024 , ScarCruft compromised the Windows and Android components of a gaming platform dedicated to Yanbian -themed games. The hackers modified the components with the BirdCall backdoor. Windows versions of BirdCall (an advanced evolution of RokRAT ), have been detected since 2021. Over the years, RokRAT has also been adapted to target macOS ( CloudMensis ) and Android ( RambleOn ), indicating that the malware family continues to be actively maintained by threat actors.
Technical capabilities of BirdCall malware
BirdCall is equipped with features typical of a backdoor, allowing for screenshot capture, keystroke logging, clipboard content theft , shell command execution, and data collection. Like RokRAT , the malware relies on legitimate cloud services, such as Dropbox and pCloud , for command-and-control (C2). BirdCall is typically deployed in a multi-stage payload chain, starting with a Ruby or Python script and containing encrypted assets (with a computer-specific key).
The Android of BirdCall resembles the Windows, while simultaneously collecting contact lists, SMS messages, call logs, media files, documents, screenshots, and ambient sound.
See also: ScarCruft uses Zoho WorkDrive and USB malware to compromise air-gapped networks

According to the analysis, the supply chain attack only affects Android APKs available for download from the platform , leaving Windows desktop clients and iOS games untouched. The download pages for two Android games hosted on sqgame[.]net have been modified to serve the malicious APKs :
Timeline and method of attack
It is currently unknown when the site was compromised and when the compromised APKs. However, it is believed that the incident occurred sometime in late 2024.Evidence has emerged that a Windows desktop client update package delivered a modified DLL from November 2024.The update package is no longer malicious.
The modified DLL included a downloader, which checks the list of running processes for analysis tools and virtual machine environments. After these checks, it proceeds to download and execute shellcode containing RokRAT . The backdoor is then used to retrieve and install BirdCall on infected hosts. The Android version of BirdCall also relies on legitimate cloud storage services for C2 communications, including pCloud , Yandex Disk , and Zoho WorkDrive .
See also: APT37 targets Windows with new Rust & Python Based Malware
The Android backdoor has seen active development and provides surveillance capabilities, such as collecting personal data and documents, taking screenshots, and creating voice recordings. This development reflects ScarCruft on multi-platform attacks, extending the threat beyond traditional Windows systems. The use of legitimate cloud services for C2 communications makes detection more difficult, as the traffic appears legitimate to network monitoring systems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

According to The Hacker News, this campaign highlights the continued evolution of threats from state-sponsored groups and the need for enhanced security measures on gaming platforms and mobile applications.
