ScarCruft Supply Chain Attack Targets Gaming Platform Users

North Korea-aligned state-sponsored hackers, tracked by researchers as ScarCruft or APT37, have executed a sophisticated supply-chain attack against a regional video game platform.

According to ESET researchers, the campaign specifically targets ethnic Koreans living in China’s Yanbian region, an area known as a primary transit point for North Korean defectors and refugees.

The ongoing attack, which likely began in late 2024, compromises both Windows and Android versions of traditional Yanbian card and board games to deliver a powerful backdoor known as BirdCall.

ScarCruft Supply Chain Attack

The attack methodology differs significantly across platforms, highlighting the APT group’s adaptability. On Windows systems, the compromise occurred through a malicious update mechanism.

The hackers intercepted the desktop client’s update process and delivered a Trojan dllrary .dll. When executed, this downloader checks the system to ensure it is not running inside a security researcher’s virtual machine.

Once cleared, it downloads shellcode that installs the RokRAT backdoor, which is then utilized to drop the more sophisticated BirdCall malware onto the victim’s machine.

To hide their tracks, the attackers replace the infected mono.dll with a clean version immediately after the infection is complete.

Yanbian Red Ten game (Source: welivesecurity)
Yanbian Red Ten game (Source: welivesecurity)

The newly discovered Android variant of BirdCall operates as a highly capable surveillance tool that harvests sensitive personal information.

Once active, the spyware covertly collects a victim’s contact lists, SMS messages, call logs, and media files.

Download page leading to trojanized games (Source: welivesecurity)
Download page leading to trojanized games (Source: welivesecurity)

It actively searches the device’s storage for specific document types, including Microsoft Office files, PDFs, and private keys, staging them for exfiltration to the attackers.

Beyond data theft, BirdCall possesses aggressive monitoring features. The malware can periodically capture screenshots of the device, utilizing a clever evasion technique that plays a silent audio file on a continuous loop to prevent the operating system from closing the background process.

The backdoor can also hijack the device’s microphone to record ambient audio.

However, researchers noted that this feature is hardcoded and only operates during a specific three-hour window in the evening.

Feature / CapabilityWindows BirdCallAndroid BirdCall
Initial AccessTrojanized Windows update (mono.dll)Trojanized game application installers (APKs)
Primary FunctionsKeylogging, credential theft, shell commands SMS/call log theft, contact harvesting
MonitoringScreen captures, clipboard monitoringScreen captures, scheduled ambient audio recording
C2 InfrastructureDropbox, pCloudZoho WorkDrive, pCloud, Yandex Disk

According to welivesecurity research, to communicate with its command-and-control servers, the malware abuses legitimate cloud storage services.

While the Windows version typically relies on Dropbox or pCloud, the Android variant primarily utilizes Zoho WorkDrive to receive commands and upload stolen data.

By routing malicious traffic through trusted enterprise services, ScarCruft successfully blends its espionage activities with normal internet traffic, making the infection incredibly difficult for standard security tools to detect.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories