Skip to main content
Mallory
Back to intelligence
state-sponsored-espionagevendor-distribution-compromiseremote-access-implantcommand-and-control-method

ScarCruft Compromised sqgame.net to Deliver BirdCall Spyware on Android and Windows

Updated 30d agoFirst seen Apr 25, 202610 sources

North Korea-linked ScarCruft (also tracked as APT37 and Reaper) compromised the gaming platform sqgame[.]net to distribute trojanized software carrying its BirdCall backdoor, according to reporting based on ESET research. The operation targeted users tied to the Yanbian Korean Autonomous Prefecture in China, a region associated with North Korean defector transit, and likely focused on defectors, activists, and related communities. Researchers said the campaign appears to have begun in late 2024, with attackers likely breaching the site’s web server and repackaging legitimate Android game APKs rather than stealing source code.

The malicious Android apps deployed a mobile variant of BirdCall capable of stealing contacts, SMS messages, call logs, files, media, and private keys, while also taking screenshots and recording ambient audio. Reporting also said ScarCruft briefly trojanized a Windows desktop client update component: a malicious mono.dll fetched RokRAT, which then installed the Windows BirdCall payload. BirdCall is described as an evolution of RokRAT and supports surveillance features including keystroke logging, clipboard theft, shell execution, and screenshot capture on Windows, while its Android command-and-control traffic blended into normal network activity and could use cloud services such as Zoho WorkDrive, pCloud, and Yandex Disk.

Share:
ScarCruft Compromised sqgame.net to Deliver BirdCall Spyware on Android and Windows
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
May 5, 20261mo ago

Cisco Talos discloses UAT-8302 and publishes IOCs

On 2026-05-05, Cisco Talos publicly disclosed UAT-8302, detailing its malware arsenal, links to other China-nexus clusters, and use of open-source and Chinese-language tooling. Talos also released detection coverage through ClamAV and Snort along with extensive file and network indicators of compromise.

May 4, 20261mo ago

ESET discloses ScarCruft's BirdCall campaign via sqgame.net

In early May 2026, ESET publicly reported that ScarCruft had compromised sqgame.net to distribute BirdCall malware to Android and Windows users in the Yanbian region. The disclosure linked the targeting to communities associated with North Korean defectors and human rights interests.

Mar 8, 20263mo ago

Breakglass publishes TernDoor and UAT-9244 technical analysis

On 2026-03-08, Breakglass Intelligence published a detailed analysis of UAT-9244's campaign, describing TernDoor's six-layer unpacking chain, custom TLS 1.3 implementation, AES-encrypted communications, named-pipe lateral movement, and embedded kernel driver. The report also identified live TernDoor command-and-control servers and shared infrastructure across the malware families.

Mar 5, 20263mo ago

Cisco Talos publicly discloses UAT-9244

On 2026-03-05, Cisco Talos publicly disclosed UAT-9244 and assessed overlap with FamousSparrow and Tropic Trooper. Talos said it could not establish a solid connection between UAT-9244 and Salt Typhoon.

Dec 1, 20256mo ago

ESET notifies sqgame of ScarCruft compromise

ESET said it notified sqgame in December 2025 about the ScarCruft supply-chain compromise affecting the platform's Android and Windows distribution infrastructure. At the time of ESET's publication in May 2026, the researchers said they had not received a response.

New ScarCruft Supply Chain Attack Hits Gaming Platform With Windows and Android Backdoors - Cyber Security News
Jan 1, 20251y ago

UAT-8302 expands operations into southeastern Europe

Cisco Talos reported that UAT-8302 also targeted government agencies in southeastern Europe during 2025. The activity showed tooling overlap with multiple previously reported China-nexus or Chinese-speaking threat clusters.

Nov 1, 20242y ago

ScarCruft trojanizes Windows sqgame.net update component

For part of the sqgame.net campaign, ScarCruft also compromised a Windows desktop client update component to deliver malware. On Windows, a trojanized mono.dll downloaded RokRAT, which then deployed the BirdCall payload.

UAT-8302 begins targeting South American governments

Cisco Talos disclosed that the China-nexus APT UAT-8302 had targeted government entities in South America since at least late 2024. The group used reconnaissance, credential theft, lateral movement, proxying, and several custom malware families to maintain long-term access.

ScarCruft starts sqgame.net supply-chain espionage campaign

ESET reported that the North Korea-aligned group ScarCruft began a supply-chain attack against sqgame.net in late 2024, targeting users in China's Yanbian region. The attackers trojanized Android game APKs with the BirdCall backdoor and likely compromised the website's web server to distribute the malware.

Oct 1, 20242y ago

Android BirdCall variant is developed

ESET found that the Android version of BirdCall used in the sqgame.net campaign was developed around October 2024, with at least seven versions identified. The malware supports surveillance functions including theft of contacts, SMS, call logs, files, screenshots, and ambient audio.

Jun 1, 20242y ago

UAT-9244 begins targeting South American telecom providers

Breakglass Intelligence assessed that the China-nexus cluster UAT-9244 had been targeting telecommunications providers in South America since at least mid-2024. The operation used multiple malware families, including the Windows backdoor TernDoor, the Linux backdoor PeerTime, and the Go-based brute-force tool BruteEntry.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.