# ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame[.]com[.]cn Targeting Yanbian Ethnic Koreans

> ESET disclosed on 2026-05-05 that North Korea-aligned APT group ScarCruft (APT37) compromised sqgame[.]com[.]cn, a Yanbian-themed gaming platform, to distribute trojanized Android games and a poisoned Windows mono.dll update. The campaign deploys an undocumented Android port of the BirdCall backdoor (internally named 'zhuagou') and chains a Windows downloader → RokRAT → BirdCall delivery, targeting ethnic Koreans and likely defectors in China's Yanbian Korean Autonomous Prefecture. Active since at least November 2024, the operation uses Zoho WorkDrive cloud storage for C2 and exfiltrates contacts, SMS, call logs, screenshots, ambient audio, .hwp/.pdf/.p12 documents, and credentials.

- **Published:** 2026-05-05T12:00:00Z
- **Last reviewed:** 2026-05-05T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0460
- **ID:** TL-2026-0460
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** APT37 (North Korea)
- **Detections:** 9 · **IOCs:** 44 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Overview

On 2026-05-05, ESET researcher Filip Jurčacko published a comprehensive analysis of an ongoing multiplatform supply-chain campaign attributed to ScarCruft (also tracked as APT37, Reaper, Group123, InkySquid, RedEyes, Ricochet Chollima), a North Korea-aligned espionage group active since at least 2012. The campaign compromised sqgame[.]com[.]cn — a video game platform tailored for ethnic Koreans living in the Yanbian Korean Autonomous Prefecture in China, a region bordering North Korea and the largest ethnic Korean community outside the Korean Peninsula and a known crossing point for North Korean refugees and defectors. ESET notified sqgame in December 2025 and received no response; trojanized files remained live on the platform at the time of public disclosure.

Victimology

ESET assesses with high confidence that the targets are ethnic Koreans in or originating from the Yanbian region, with the secondary intent of collecting intelligence on North Korean refugees and defectors of interest to the Pyongyang regime. The compromised platform hosts traditional Yanbian card and board games and is used for organized tournaments, suggesting victims were socially engineered through trusted, culturally-relevant content rather than indiscriminate phishing. iOS games on the platform were not weaponized, likely due to the friction of bypassing Apple's App Store review process.

Android attack chain

Two Android games on the sqgame website were trojanized: 延边红十 (Yanbian Red Ten, hosted as ybht.apk) and 新画图 (New Drawing, hosted as sqybhs.apk). ESET assesses that ScarCruft did not gain access to the games' source code; instead, the operators repackaged the original APKs by patching AndroidManifest.xml to redirect the entry-point activity to malicious classes (com.example.zhuagou.SplashScreen in early versions, com.mob.util.MobSs in v2.0), then chained execution back to the legitimate game's main activity to avoid suspicion. Seven distinct backdoor versions were identified across approximately eight months — version 1.0 (~October 2024) through version 2.0 (~June 2025). The encoding scheme bd_version = MAJOR<<5 | MINOR was reverse-engineered from the configuration field. Victims downloaded the APKs via mobile browsers directly from the trusted sqgame domain; the trojanized files were never observed on Google Play.

Windows attack chain

The Windows desktop client itself was clean, but its update package hosted at http://xiazai.sqgame.com[.]cn/dating/20240429.zip delivered a trojanized mono.dll (SHA-1 95BDB94F6767A3CCE6D92363BBF5BC84B786BDB0) that ESET telemetry traced back to at least November 2024. The malicious mono.dll embeds a downloader (SHA-1 409C5ACAED587F62F7E23DA47F72C4D9EC3144D9) that performs sandbox/VM/analysis-tool checks via running-process enumeration before fetching encrypted shellcode hosting the RokRAT backdoor from compromised South Korean websites (lawwell.co.kr, colorncopy.co.kr, swr.co.kr, cndsoft.co.kr). After execution, the downloader replaces the trojanized DLL with a clean copy fetched from another compromised South Korean site (sejonghaeun[.]com), erasing the on-disk indicator. RokRAT then downloads and installs the more sophisticated Windows BirdCall backdoor (closely matching public sample SHA-1 B06110E0FEB7592872E380B7E3B8F77D80DD1108 uploaded from China on 2024-07-15).

Android BirdCall (zhuagou) capabilities

The Android port implements a subset of the Windows backdoor's command set but is purpose-built for mobile espionage. Capabilities include: full directory listing of primary shared external storage; collection of contacts, SMS messages, and call logs (mobile MITRE T1636.002/003/004); periodic screenshot capture (scr flag) using the startForeground API and a silent looping MP3 trick to keep the trojanized app alive in the background (T1541 Foreground Persistence); microphone audio recording strangely time-windowed to 19:00–22:00 local time (rec flag, T1429); device/network fingerprinting (brand, model, OS, kernel, root status, IMEI, IP, MAC, network type, RAM, storage, battery temp); IP geolocation via ipinfo[.]io/json (T1430); and periodic search/exfiltration of files matching .jpg, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .txt, .hwp, .pdf, .m4a, .p12 — note that .hwp (Hancom Office) and .p12 (PKCS#12 private key/certificate) extensions strongly indicate Korean-government and credential-theft targeting. Configuration is JSON-formatted, persisted to the app's data directory under a device-specific path, and supports an external override loaded from JPG steganography (encrypted overlay) hosted on compromised South Korean sites (1980food.co.kr, inodea.com).

C2 infrastructure

Command-and-control runs entirely over HTTPS to legitimate cloud storage providers (T1102.002 Web Service: Bidirectional Communication) using the okhttp3 library. Zoho WorkDrive is the active provider; pCloud and Yandex Disk are supported but unused in observed samples. ESET enumerated 12 distinct Zoho WorkDrive accounts/drives (e.g., tomasalfred37@zohomail[.]com, kalimaxim279@zohomail[.]com, smithbentley0617@zohomail[.]com) used as dead-drops. Decrypted commands begin with the magic DWORD 0x2A7B4C33, identical to the Windows backdoor — strong same-author confirmation. Commands include MP_GET_DATA (0x56), MP_SEND_FILE (0x59, supports backdoor self-update via APK download), MP_SET_CLOUD (0x4A, rotate C2 credentials), MP_SET_FILESEARCH_EXTENTION (0x48), MP_SET_THREADS (0x49, toggle screenshot/audio recording), MP_ACTION_FILE_OR_DIRECTORY (0x4F), MP_ACTION_KILLME (0x4D), and MP_SET_MODE (0x4C).

Attribution

Attribution to ScarCruft is HIGH confidence: BirdCall is an ESET-established ScarCruft tool first attributed in 2021 ETI reporting; the Windows campaign delivers RokRAT (longstanding ScarCruft RAT, publicly documented by S2W and AhnLab); the multi-stage loader uses environmental keying with a computer-specific decryption key (a documented ScarCruft TTP); and the abuse of compromised legitimate South Korean web infrastructure for staging is a textbook ScarCruft pattern. Targeting of ethnic Korean diaspora and defectors aligns with declared DPRK intelligence priorities.

Defensive impact

While no CVE applies (this is a campaign, not a vulnerability), the operation demonstrates the continued viability of supply-chain compromise against niche, culturally-targeted platforms; the use of legitimate cloud storage for C2 evades most network-egress detection; and the .hwp/.p12/.hwp file targeting indicates likely follow-on operations against South Korean government and certificate-protected resources. Defenders supporting at-risk diaspora populations or Korean-government-adjacent organizations should prioritize Android EDR coverage, Zoho WorkDrive egress monitoring, and YARA hunting for the published hashes.

## MITRE ATT&CK

- T1584 Compromise Infrastructure
- T1585 Establish Accounts
- T1587 Develop Capabilities
- T1608 Stage Capabilities
- T1195 Supply Chain Compromise
- T1474 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1027 Obfuscated Files or Information
- T1070 Indicator Removal
- T1112 Modify Registry
- T1140 Deobfuscate/Decode Files or Information
- T1480 Execution Guardrails
- T1497 Virtualization/Sandbox Evasion
- T1406 Obfuscated Files or Information
- T1407 Download New Code at Runtime
- T1541 Foreground Persistence
- T1555 Credentials from Password Stores
- T1046 Network Service Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1420 File and Directory Discovery
- T1422 System Network Configuration Discovery
- T1426 System Information Discovery
- T1005 Data from Local System
- T1056 Input Capture
- T1113 Screen Capture
- T1115 Clipboard Data
- T1119 Automated Collection
- T1125 Video Capture
- T1560 Archive Collected Data
- T1429 Audio Capture
- T1430 Location Tracking
- T1513 Screen Capture
- T1532 Archive Collected Data
- T1533 Data from Local System
- T1636 Protected User Data
- T1071 Application Layer Protocol
- T1090 Proxy
- T1102 Web Service
- T1437 Application Layer Protocol

## Sources

- [A rigged game: ScarCruft compromises gaming platform in a supply-chain attack (ESET WeLiveSecurity, Filip Jurčacko)](https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/)
- [ESET IoC GitHub repository — ScarCruft sqgame supply-chain](https://github.com/eset/malware-ioc)
- [ScarCruft hackers push BirdCall Android malware via game platform (BleepingComputer)](https://www.bleepingcomputer.com/news/security/scarcruft-hackers-push-birdcall-android-malware-via-game-platform/)
- [ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows (The Hacker News)](https://thehackernews.com/2026/05/scarcruft-hacks-gaming-platform-to.html)
- [North Korean hackers trojanize gaming platform to spy on ethnic Koreans in China (Help Net Security)](https://www.helpnetsecurity.com/2026/05/05/china-scarcruft-supply-chain-attack/)
- [MITRE ATT&CK Group G0067 — APT37](https://attack.mitre.org/groups/G0067/)
- [MITRE ATT&CK Software S0240 — ROKRAT](https://attack.mitre.org/software/S0240/)
- [S2W LAB — RokRAT advanced variant analysis (BirdCall lineage)](https://medium.com/s2wblog)
- [AhnLab — RokRAT analysis (BirdCall predecessor)](https://asec.ahnlab.com/en/)
- [ESET research — Who's swimming in South Korean waters? Meet ScarCruft's Dolphin](https://www.welivesecurity.com/2022/11/30/whos-swimming-south-korean-waters-meet-scarcrufts-dolphin/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0460
