Back Escudodigital North Korean hackers spy on China via video game platform | DigitalShield
A cross-platform supply chain attack carried out by the APT group ScarCruft , aligned with North Korea, has been detected by experts from ESET Research . The campaign focuses on the Yanbian region in China, an area with a presence of ethnic Korean population and a transit point for North Korean refugees and defectors.
The operation, likely ongoing since late 2024, compromised the Windows and Android components of a gaming platform centered on Yanbian-themed games. Both were trojanized by implanting a backdoor called BirdCall , initially known to target only Windows, with its Android version later identified as part of this operation.
The Android version of BirdCall implements a subset of the capabilities of its Windows equivalent. It can collect contacts, SMS messages, call logs, documents, multimedia files, and private keys, as well as take screenshots and record ambient audio. This version, according to researchers, has been actively developed over several months, and at least seven variants have been deployed .
Since the compromised website is oriented towards the Yanbian population and their traditional games, it has been determined that the main targets are the ethnic Koreans living in this region . It is likely that the campaign was aimed at gathering information on individuals considered of interest to the North Korean regime, most likely refugees or defectors.
The Windows client of the platform was compromised through a malicious update that introduced the RokRAT backdoor , which deployed the more sophisticated BirdCall. The backdoor for Windows was initially discovered in 2021 and attributed to ScarCruft in threat intelligence reports.
This version has extensive espionage capabilities , such as screen capture, keystroke logging, clipboard content logging, credential and file theft, and shell command execution. To communicate with its command and control (C&C) servers, it uses legitimate cloud storage services like Dropbox or pCloud, as well as compromised websites.
ScarCruft, also known as APT37 or Reaper , has been operating since at least 2012 and is suspected to be a North Korean espionage group. It primarily focuses on South Korea, although it has also targeted other Asian countries, especially against government and military organizations, as well as companies linked to North Korean interests. The group has also attacked North Korean defectors.
A cross-platform supply chain attack carried out by the APT group ScarCruft , aligned with North Korea, has been detected by experts from ESET Research . The campaign focuses on the Yanbian region in China, an area with a presence of ethnic Korean population and a transit point for North Korean refugees and defectors.
The operation, likely ongoing since late 2024, compromised the Windows and Android components of a gaming platform centered on Yanbian-themed games. Both were trojanized by implanting a backdoor called BirdCall , initially known to target only Windows, with its Android version later identified as part of this operation.
The Android version of BirdCall implements a subset of the capabilities of its Windows equivalent. It can collect contacts, SMS messages, call logs, documents, multimedia files, and private keys, as well as take screenshots and record ambient audio. This version, according to researchers, has been actively developed over several months, and at least seven variants have been deployed .
Since the compromised website is oriented towards the Yanbian population and their traditional games, it has been determined that the main targets are the ethnic Koreans living in this region . It is likely that the campaign was aimed at gathering information on individuals considered of interest to the North Korean regime, most likely refugees or defectors.
The Windows client of the platform was compromised through a malicious update that introduced the RokRAT backdoor , which deployed the more sophisticated BirdCall. The backdoor for Windows was initially discovered in 2021 and attributed to ScarCruft in threat intelligence reports.
This version has extensive espionage capabilities , such as screen capture, keystroke logging, clipboard content logging, credential and file theft, and shell command execution. To communicate with its command and control (C&C) servers, it uses legitimate cloud storage services like Dropbox or pCloud, as well as compromised websites.
ScarCruft, also known as APT37 or Reaper , has been operating since at least 2012 and is suspected to be a North Korean espionage group. It primarily focuses on South Korea, although it has also targeted other Asian countries, especially against government and military organizations, as well as companies linked to North Korean interests. The group has also attacked North Korean defectors.
Become a premium member for free!
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
