ScarCruft has widened BirdCall from a desktop backdoor into a mobile surveillance tool. That breaks the usual assumption that watching Windows clients is enough, because the same lure now reaches phones through trojanized APKs installed outside the app store.
ESET says the Android version has been in development since around October 2024, with at least seven variants. The compromised sqgame.net game packages are still available, and the Android payload can collect SMS, call logs, contacts, media, private keys, and device data.
This is a phase shift in the campaign, not a one-off variant. The risk now extends to persistent monitoring of users’ phones in the target community, even when the desktop side is already understood.
North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware
Researchers at cybersecurity firm ESET attributed the campaign to APT37 and said the hackers used a backdoor attached to a suite of card games from a company called Sqgame.
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games.