ScarCruft Moves BirdCall From Windows to Android

ScarCruft has widened BirdCall from a desktop backdoor into a mobile surveillance tool. That breaks the usual assumption that watching Windows clients is enough, because the same lure now reaches phones through trojanized APKs installed outside the app store. ESET says the Android version has been in development since around October 2024, with at least seven variants. The compromised sqgame.net game packages are still available, and the Android payload can collect SMS, call logs, contacts, media, private keys, and device data. This is a phase shift in the campaign, not a one-off variant. The risk now extends to persistent monitoring of users’ phones in the target community, even when the desktop side is already understood.

Part of the PlainSec briefing for 2026-05-07

Sources