ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame[.]com[.]cn Targeting Yanbian Ethnic Koreans — Threadlinqs Intelligence
As of 2026-05-30, ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame[.]com[.]cn Targeting Yanbian Ethnic Koreans is a high-severity apt threat attributed to APT37 (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 44 indicators of compromise.
Threat ID: TL-2026-0460 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: APT37 · North Korea · ESPIONAGE
ESET disclosed on 2026-05-05 that North Korea-aligned APT group ScarCruft (APT37) compromised sqgame[.]com[.]cn, a Yanbian-themed gaming platform, to distribute trojanized Android games and a poisoned
Overview
On 2026-05-05, ESET researcher Filip Jurčacko published a comprehensive analysis of an ongoing multiplatform supply-chain campaign attributed to ScarCruft (also tracked as APT37, Reaper, Group123, InkySquid, RedEyes, Ricochet Chollima), a North Korea-aligned espionage group active since at least 2012. The campaign compromised sqgame[.]com[.]cn — a video game platform tailored for ethnic Koreans living in the Yanbian Korean Autonomous Prefecture in China, a region bordering North Korea and the largest ethnic Korean community outside the Korean Peninsula and a known crossing point for North Korean refugees and defectors. ESET notified sqgame in December 2025 and received no response; trojanized files remained live on the platform at the time of public disclosure.
Victimology
ESET assesses with high confidence that the targets are ethnic Koreans in or originating from the Yanbian region, with the secondary intent of collecting intelligence on North Korean refugees and defectors of interest to the Pyongyang regime. The compromised platform hosts traditional Yanbian card and board games and is used for organized tournaments, suggesting victims were socially engineered through trusted, culturally-relevant content rather than indiscriminate phishing. iOS games on the platform were not weaponized, likely due to the friction of bypassing Apple's App Store review process.
Android attack chain
Two Android games on the sqgame website were trojanized: 延边红十 (Yanbian Red Ten, hosted as ybht.apk) and 新画图 (New Drawing, hosted as sqybhs.apk). ESET assesses that ScarCruft did not gain access to the games' source code; instead, the operators repackaged the original APKs by patching AndroidManifest.xml to redirect the entry-point activity to malicious classes (com.example.zhuagou.SplashScreen in early versions, com.mob.util.MobSs in v2.0), then chained execution back to the legitimate game's main activity to avoid suspicion. Seven distinct backdoor versions were identified across approximately eight months — version 1.0 (~October 2024) through version 2.0 (~June 2025). The encoding scheme bd_version = MAJOR<<5 | MINOR was reverse-engineered from the configuration field. Victims downloaded the APKs via mobile browsers directly from the trusted sqgame domain; the trojanized files were never observed on Google Play.
Windows attack chain
The Windows desktop client itself was clean, but its update package hosted at http://xiazai.sqgame.com[.]cn/dating/20240429.zip delivered a trojanized mono.dll (SHA-1 95BDB94F6767A3CCE6D92363BBF5BC84B786BDB0) that ESET telemetry traced back to at least November 2024. The malicious mono.dll embeds a downloader (SHA-1 409C5ACAED587F62F7E23DA47F72C4D9EC3144D9) that performs sandbox/VM/analysis-tool checks via running-process enumeration before fetching encrypted shellcode hosting the RokRAT backdoor from compromised South Korean websites (lawwell.co.kr, colorncopy.co.kr, swr.co.kr, cndsoft.co.kr). After execution, the downloader replaces the trojanized DLL with a clean copy fetched from another compromised South Korean site (sejonghaeun[.]com), erasing the on-disk indicator. RokRAT then downloads and installs the more sophisticated Windows BirdCall backdoor (closely matching public sample SHA-1 B06110E0FEB7592872E380B7E3B8F77D80DD1108 uploaded from China on 2024-07-15).
Android BirdCall (zhuagou) capabilities
The Android port implements a subset of the Windows backdoor's command set but is purpose-built for mobile espionage. Capabilities include: full directory listing of primary shared external storage; collection of contacts, SMS messages, and call logs (mobile MITRE T1636.002/003/004); periodic screenshot capture (scr flag) using the startForeground API and a silent looping MP3 trick to keep the trojanized app alive in the background (T1541 Foreground Persistence); microphone audio recording strangely time-windowed to 19:00–22:00 local time (rec flag, T1429); device/network fingerprinting (brand, mod
Weaknesses (CWE)
CWE-506, CWE-1357, CWE-829, CWE-494
Target sectors: civil society, diaspora communities, government, media, ngo, human rights, academia
Target regions: China (Yanbian Korean Autonomous Prefecture, Jilin), South Korea, North Korea defector networks, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 44 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1584, T1585, T1587, T1608, T1195, T1474, T1059, T1027, T1070, T1112