Threats · 131 days ago
ScarCruft has widened BirdCall from a desktop backdoor into a mobile surveillance tool. That breaks the usual assumption that watching Windows clients is enough, because the same lure now reaches phones through trojanized APKs installed outside the app store.
ESET says the Android version has been in development since around October 2024, with at least seven variants. The compromised sqgame.net game packages are still available, and the Android payload can collect SMS, call logs, contacts, media, private keys, and device data.
This is a phase shift in the campaign, not a one-off variant. The risk now extends to persistent monitoring of users’ phones in the target community, even when the desktop side is already understood.
4 sources covering this story
The Record from Recorded Future
North Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malware
Researchers at cybersecurity firm ESET attributed the campaign to APT37 and said the hackers used a backdoor attached to a suite of card games from a company called Sqgame.
ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows
ScarCruft spreads BirdCall via sqgame.net since late 2024, targeting Android users, enabling surveillance and data theft.
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games.
ScarCruft hackers push BirdCall Android malware via game platform
The North Korean hacker group APT37 has been delivering an Android version of a backdoor called BirdCall in a supply-chain attack through a video game platform.
Part of the PlainSec briefing for 2026-05-07