ScarCruft ha ampliato BirdCall da una backdoor desktop a uno strumento di sorveglianza mobile. Questo rompe la consueta supposizione che osservare i client Windows sia sufficiente, perché la stessa esca ora raggiunge anche i telefoni tramite APK trojanizzati installati fuori dall’app store.
North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware
Researchers at cybersecurity firm ESET attributed the campaign to APT37 and said the hackers used a backdoor attached to a suite of card games from a company called Sqgame.
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games.