Threat reportAPTTL-2026-0460

ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame[.]com[.]cn Targeting Yanbian Ethnic Koreans

highACTIVE

ScarCruft (APT37) BirdCall Android Variant (TL-2026-0460), also tracked as BirdCall Android Campaign, is a high-severity advanced persistent threat campaign, first published 2026-05-05. It is attributed to APT37 (North Korea) with high confidence, affects sqgame (sqgame.com.cn) Yanbian Red Ten (延边红十) Android Game, maps to 45 MITRE ATT&CK techniques (T1005, T1020, T1027), and is covered by 9 detection rules and 44 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
45MITRE ATT&CK
Actors
1APT37
Detection rules
9SPL · KQL · Sigma
IOCs
44Indicators of compromise

Key facts for TL-2026-0460

Threat ID
TL-2026-0460
Also known as
BirdCall Android Campaign, zhuagou, Operation Rigged Game, sqgame Supply-Chain Compromise, Yanbian Supply-Chain Operation
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
APT37
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
civil society, diaspora communities, government, media, ngo, human rights, academia
Target regions
China (Yanbian Korean Autonomous Prefecture, Jilin), South Korea, North Korea defector networks, Asia-Pacific
Detection rules
9
Indicators of compromise
44

Malware and tooling in ScarCruft (APT37) BirdCall Android Variant

Malware and tooling: BirdCall, BirdCall (zhuagou) — custom ScarCruft backdoor, RokRAT

How ScarCruft (APT37) BirdCall Android Variant works

ESET disclosed on 2026-05-05 that North Korea-aligned APT group ScarCruft (APT37) compromised sqgame[.]com[.]cn, a Yanbian-themed gaming platform, to distribute trojanized Android games and a poisoned Windows mono.dll update. The campaign deploys an undocumented Android port of the BirdCall backdoor (internally named 'zhuagou') and chains a Windows downloader → RokRAT → BirdCall delivery, targeting ethnic Koreans and likely defectors in China's Yanbian Korean Autonomous Prefecture. Active since at least November 2024, the operation uses Zoho WorkDrive cloud storage for C2 and exfiltrates contacts, SMS, call logs, screenshots, ambient audio, .hwp/.pdf/.p12 documents, and credentials.

Overview

On 2026-05-05, ESET researcher Filip Jurčacko published a comprehensive analysis of an ongoing multiplatform supply-chain campaign attributed to ScarCruft (also tracked as APT37, Reaper, Group123, InkySquid, RedEyes, Ricochet Chollima), a North Korea-aligned espionage group active since at least 2012. The campaign compromised sqgame[.]com[.]cn — a video game platform tailored for ethnic Koreans living in the Yanbian Korean Autonomous Prefecture in China, a region bordering North Korea and the largest ethnic Korean community outside the Korean Peninsula and a known crossing point for North Korean refugees and defectors. ESET notified sqgame in December 2025 and received no response; trojanized files remained live on the platform at the time of public disclosure.

Victimology

ESET assesses with high confidence that the targets are ethnic Koreans in or originating from the Yanbian region, with the secondary intent of collecting intelligence on North Korean refugees and defectors of interest to the Pyongyang regime. The compromised platform hosts traditional Yanbian card and board games and is used for organized tournaments, suggesting victims were socially engineered through trusted, culturally-relevant content rather than indiscriminate phishing. iOS games on the platform were not weaponized, likely due to the friction of bypassing Apple's App Store review process.

Android attack chain

Two Android games on the sqgame website were trojanized: 延边红十 (Yanbian Red Ten, hosted as ybht.apk) and 新画图 (New Drawing, hosted as sqybhs.apk). ESET assesses that ScarCruft did not gain access to the games' source code; instead, the operators repackaged the original APKs by patching AndroidManifest.xml to redirect the entry-point activity to malicious classes (com.example.zhuagou.SplashScreen in early versions, com.mob.util.MobSs in v2.0), then chained execution back to the legitimate game's main activity to avoid suspicion. Seven distinct backdoor versions were identified across approximately eight months — version 1.0 (~October 2024) through version 2.0 (~June 2025). The encoding scheme bd_version = MAJOR<<5 | MINOR was reverse-engineered from the configuration field. Victims downloaded the APKs via mobile browsers directly from the trusted sqgame domain; the trojanized files were never observed on Google Play.

Windows attack chain

The Windows desktop client itself was clean, but its update package hosted at http://xiazai.sqgame.com[.]cn/dating/20240429.zip delivered a trojanized mono.dll (SHA-1 95BDB94F6767A3CCE6D92363BBF5BC84B786BDB0) that ESET telemetry traced back to at least November 2024. The malicious mono.dll embeds a downloader (SHA-1 409C5ACAED587F62F7E23DA47F72C4D9EC3144D9) that performs sandbox/VM/analysis-tool checks via running-process enumeration before fetching encrypted shellcode hosting the RokRAT backdoor from compromised South Korean websites (lawwell.co.kr, colorncopy.co.kr, swr.co.kr, cndsoft.co.kr). After execution, the downloader replaces the trojanized DLL with a clean copy fetched from another compromised South Korean site (sejonghaeun[.]com), erasing the on-disk indicator. RokRAT then downloads and installs the more sophisticated Windows BirdCall backdoor (closely matching public sample SHA-1 B06110E0FEB7592872E380B7E3B8F77D80DD1108 uploaded from China on 2024-07-15).

Android BirdCall (zhuagou) capabilities

The Android port implements a subset of the Windows backdoor's command set but is purpose-built for mobile espionage. Capabilities include: full directory listing of primary shared external storage; collection of contacts, SMS messages, and call logs (mobile MITRE T1636.002/003/004); periodic screenshot capture (scr flag) using the startForeground API and a silent looping MP3 trick to keep the trojanized app alive in the background (T1541 Foreground Persistence); microphone audio recording strangely time-windowed to 19:00–22:00 local time (rec flag, T1429); device/network fingerprinting (brand, model, OS, kernel, root status, IMEI, IP, MAC, network type, RAM, storage, battery temp); IP geolocation via ipinfo[.]io/json (T1430); and periodic search/exfiltration of files matching .jpg, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .txt, .hwp, .pdf, .m4a, .p12 — note that .hwp (Hancom Office) and .p12 (PKCS#12 private key/certificate) extensions strongly indicate Korean-government and credential-theft targeting. Configuration is JSON-formatted, persisted to the app's data directory under a device-specific path, and supports an external override loaded from JPG steganography (encrypted overlay) hosted on compromised South Korean sites (1980food.co.kr, inodea.com).

C2 infrastructure

Command-and-control runs entirely over HTTPS to legitimate cloud storage providers (T1102.002 Web Service: Bidirectional Communication) using the okhttp3 library. Zoho WorkDrive is the active provider; pCloud and Yandex Disk are supported but unused in observed samples. ESET enumerated 12 distinct Zoho WorkDrive accounts/drives (e.g., tomasalfred37@zohomail[.]com, kalimaxim279@zohomail[.]com, smithbentley0617@zohomail[.]com) used as dead-drops. Decrypted commands begin with the magic DWORD 0x2A7B4C33, identical to the Windows backdoor — strong same-author confirmation. Commands include MP_GET_DATA (0x56), MP_SEND_FILE (0x59, supports backdoor self-update via APK download), MP_SET_CLOUD (0x4A, rotate C2 credentials), MP_SET_FILESEARCH_EXTENTION (0x48), MP_SET_THREADS (0x49, toggle screenshot/audio recording), MP_ACTION_FILE_OR_DIRECTORY (0x4F), MP_ACTION_KILLME (0x4D), and MP_SET_MODE (0x4C).

Attribution

Attribution to ScarCruft is HIGH confidence: BirdCall is an ESET-established ScarCruft tool first attributed in 2021 ETI reporting; the Windows campaign delivers RokRAT (longstanding ScarCruft RAT, publicly documented by S2W and AhnLab); the multi-stage loader uses environmental keying with a computer-specific decryption key (a documented ScarCruft TTP); and the abuse of compromised legitimate South Korean web infrastructure for staging is a textbook ScarCruft pattern. Targeting of ethnic Korean diaspora and defectors aligns with declared DPRK intelligence priorities.

Defensive impact

While no CVE applies (this is a campaign, not a vulnerability), the operation demonstrates the continued viability of supply-chain compromise against niche, culturally-targeted platforms; the use of legitimate cloud storage for C2 evades most network-egress detection; and the .hwp/.p12/.hwp file targeting indicates likely follow-on operations against South Korean government and certificate-protected resources. Defenders supporting at-risk diaspora populations or Korean-government-adjacent organizations should prioritize Android EDR coverage, Zoho WorkDrive egress monitoring, and YARA hunting for the published hashes.

MITRE ATT&CK techniques used in TL-2026-0460

Collection

T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection; T1125 Video Capture; T1429 Audio Capture; T1430 Location Tracking; T1513 Screen Capture; T1532 Archive Collected Data; T1533 Data from Local System; T1560 Archive Collected Data; T1636 Protected User Data

Exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service; T1646 Exfiltration Over C2 Channel

Defense Evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1420 File and Directory Discovery; T1422 System Network Configuration Discovery; T1426 System Information Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service

defense-impairment

T1112 Modify Registry

Initial Access

T1195 Supply Chain Compromise

defense-evasion

T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1541 Foreground Persistence

command-and-control

T1437 Application Layer Protocol; T1481 Web Service

initial-access

T1474 Supply Chain Compromise

Credential Access

T1555 Credentials from Password Stores

Resource Development

T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

Affected products and versions in ScarCruft (APT37) BirdCall Android Variant

  • sqgame (sqgame.com.cn) — Yanbian Red Ten (延边红十) Android Game
    Vulnerable versions: all builds distributed via sqgame.com.cn from late 2024 through 2026-05-05
  • sqgame (sqgame.com.cn) — New Drawing (新画图) Android Game
    Vulnerable versions: all builds distributed via sqgame.com.cn from late 2024 through 2026-05-05
  • sqgame (sqgame.com.cn) — sqgame Windows Desktop Client (mono.dll update package)
    Vulnerable versions: update package 20240429.zip served from xiazai.sqgame.com.cn — malicious from at least November 2024 through an unknown end date
    Fixed in: Update package was clean as of ESET writing (May 2026); supply-chain hygiene of vendor remains unverified
  • Google — Android (general)
    Vulnerable versions: any Android version capable of installing third-party APKs from a browser
  • Microsoft — Windows (general)
    Vulnerable versions: any Windows host running the trojanized sqgame desktop client mono.dll

Remediation for ScarCruft (APT37) BirdCall Android Variant

Patches

  • No vendor patch — sqgame[.]com[.]cn has not responded to ESET's December 2025 disclosure. The mono.dll update package was no longer malicious as of ESET's writing, but the trojanized APKs remained live on the platform.

Immediate actions

  • Block the malicious sqgame[.]com[.]cn subdomain and all listed staging IPs/domains at perimeter and DNS resolvers.
  • Identify and uninstall any APK with package paths containing com.example.zhuagou or com.mob.util.MobSs; review devices that downloaded ybht.apk or sqybhs.apk from sqgame[.]com[.]cn.
  • Hunt for the published SHA-1 hashes on Android EDR and Windows EDR, plus the trojanized mono.dll hash (95BDB94F6767A3CCE6D92363BBF5BC84B786BDB0) on any host running the sqgame Windows client.
  • Audit Zoho WorkDrive egress traffic for outbound HTTPS sessions from Android devices; investigate any device communicating with workdrive.zoho APIs that is not on a corporate-approved Zoho tenant.
  • Reset credentials and revoke .p12 certificates for any user whose Android device is suspected of compromise — the backdoor specifically harvests private key files.

Workarounds

  • Discontinue use of sqgame[.]com[.]cn games until the platform is verifiably remediated.
  • If sqgame must be retained, install only from Google Play (sqgame is not present there — treat any sqgame APK as malicious) and avoid the Windows client entirely until the vendor confirms supply-chain hygiene.
  • Where Android use is required, route mobile traffic through an inspecting VPN/MTD that blocks the listed staging domains and Zoho WorkDrive endpoints not on an approved-tenant allowlist.

Longer-term hardening

  • Deploy mobile EDR/MTD with behavioral detection on devices used by staff, family members, or contacts in at-risk diaspora communities (Yanbian, defector networks, Korean reunification advocacy groups).
  • Restrict Android sideloading via MDM (block Settings > Install unknown apps) for managed devices; require Play Protect and Play Store-only installs.
  • Build allow-listed cloud-storage egress policies; alert on first-seen connections to pCloud, Yandex Disk, or Zoho WorkDrive from devices that have no business need.
  • Establish a YARA/Sigma library tracking BirdCall command magic 0x2A7B4C33, the bd_version field encoding, and the configuration JSON schema for retroactive hunting.
  • Expand Korean-language file-format DLP coverage (.hwp Hancom Office documents) and certificate-store monitoring (.p12) on endpoints used by Korean-government partners or analysts.

Weaknesses (CWE) in ScarCruft (APT37) BirdCall Android Variant

CWE-506, CWE-1357, CWE-829, CWE-494

Timeline of ScarCruft (APT37) BirdCall Android Variant

  • Android BirdCall version 1.0 compiled (per ESET version-history analysis); earliest known build of the Android port (zhuagou).
  • ESET telemetry first observes the trojanized mono.dll inside the sqgame Windows update package 20240429.zip; compromised lawwell.co.kr (221.143.43.214) used to host shellcode and the clean replacement mono library.
  • Compromised South Korean site 1980food.co.kr (211.239.117.117) first observed hosting Android BirdCall encrypted configuration JPG.
  • Additional compromised South Korean sites colorncopy.co.kr / swr.co.kr (222.231.2.20), sejonghaeun.com (222.231.2.23), and cndsoft.co.kr (222.231.2.41) operationalized for shellcode and clean-mono staging.
  • Android BirdCall version 2.0 compiled (per ESET version-history analysis); introduces obfuscation (MITRE T1406) and the new entry-class com.mob.util.MobSs.
  • Compromised South Korean site inodea.com (114.108.128.157) added to Android BirdCall configuration-staging rotation.
  • ESET captures the malicious APKs ybht.apk (SHA-1 03E3ECE9F48CF4104AAFC535790CA2FB3C6B26CF) and sqybhs.apk (SHA-1 FC0C691DB7E2D2BD3B0B4C1E24D18DF72168B7D9) directly from sqgame[.]com[.]cn — confirming live distribution.
  • ESET notifies sqgame of the compromise; receives no response. Trojanized APKs remain live on the platform.
  • BleepingComputer, The Hacker News, and Help Net Security publish coverage; Android BirdCall added to ESET detection as Android/Spy.Agent.EGE / Android/Spy.Agent.EXM, Windows components as Win32/TrojanDownloader.Agent.ILQ and Win64/Agent.EGN.
  • ESET WeLiveSecurity publishes 'A rigged game: ScarCruft compromises gaming platform in a supply-chain attack' by Filip Jurčacko, releasing IoCs, MITRE mappings, and the first public analysis of Android BirdCall (zhuagou).
  • As of 2026-05-29, this APT37/ScarCruft (DPRK) supply-chain espionage campaign remains active: ESET's 2026-05-05 disclosure reported trojanized sqgame Android APKs still live (vendor unresponsive, no takedown). ScarCruft is demonstrably ongoing in 2026 (Facebook/RokRAT, Ruby Jumper air-gap campaigns); actor and BirdCall/RokRAT tooling persist, no CVE/patch applies.

Sources cited for ScarCruft (APT37) BirdCall Android Variant

Detection coverage for TL-2026-0460

As of 2026-05-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0460 across Splunk SPL, Microsoft KQL and Sigma, covering 44 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
44 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats