BirdCall is a North Korea-linked backdoor associated with ScarCruft, also tracked as APT37, Reaper, and Ricochet Chollima. First documented as a Windows malware family and later expanded to Android, it is used in espionage operations focused on surveillance and theft of victim data. BirdCall has been tied to campaigns targeting ethnic Koreans in China’s Yanbian region, including individuals assessed to be of interest to the North Korean regime such as refugees and defectors.
On Windows, BirdCall is a backdoor with capabilities including screenshot capture, keylogging, clipboard theft, file theft, credential theft, and shell command execution. In observed campaigns it has been delivered through multistage infection chains and, in one supply-chain operation, via a malicious update path involving a trojanized component that deployed RokRAT before installing BirdCall. The Windows tooling also showed anti-analysis behavior in the preceding downloader stage.
On Android, BirdCall functions as a spyware-capable backdoor embedded into trojanized applications. In a notable supply-chain campaign, attackers repackaged legitimate game APKs distributed outside Google Play so the malware executed silently before handing control back to the expected application. The Android variant collects contacts, SMS messages, call logs, device and network metadata, screenshots, documents, media files, and private keys, and can record ambient audio and, in some reporting, phone calls. It also performs directory listing and targeted file collection for exfiltration. Some variants were observed using cloud storage services for command and control, especially Zoho WorkDrive, with support for additional cloud providers noted in the codebase.
BirdCall is a multiplatform espionage malware family whose operational use is closely aligned with ScarCruft’s long-running intelligence collection mission against South Korean and other regional targets. Delivery observed at high confidence includes trojanized software in a supply-chain context and Android apps masquerading as legitimate software such as games and messaging applications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Detailed Analysis of BirdCall Malware: Masquerading as Zangi Messenger" published by S2W. #Scarcruft, #BirdCall
34 distinct techniques documented for this family, organized by ATT&CK tactic.
ScarCruft compromised South Korean websites to host payloads and configurations. ScarCruft compromised the sqgame website to perform a supply-chain attack.
"victims typically downloaded the compromised games through a web browser on their devices and installed them directly, without going through the Google Play store."
"We were unable to determine when the website was first compromised and the supply-chain attack started," Jurčacko said... the initial file downloaded from the Sqgame website by victims was not malicious. It became malicious due to a subsequent update package delivered by the platform that had been compromised since at least November 2024.
After dropping the payload, it replaces itself with a clean copy to erase evidence.
BirdCall decrypts strings and loading chain components.
BirdCall’s loading chain has components encrypted with a computer-specific key.
BirdCall can scan a range of IPs and ports with an HTTP GET request.
It connects to cloud storage using hardcoded credentials and uploads data including RAM, IMEI, IP and MAC address, and geolocation.
"Through BirdCall, APT37 is able to collect contact information, SMS texts, call logs, media files and private keys... It also searches any shared external storage devices for specific file types."
"The backdoor, named BirdCall by the researchers, allowed APT37 to take screenshots..."
BirdCall can periodically collect files with certain extensions from local and removable drives.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BirdCall is the named malware discussed in the post. It is described as malware masquerading as Zangi Messenger, indicating a trojanized or impersonation-based delivery method. The post also associates it with ScarCruft.
Related Articles: NGate Android malware uses HandyPay NFC app to steal card data | ScarCruft hackers push BirdCall Android malware via game platform
The content only references BirdCall by name as Android malware in a related article link; no further behavioral details are provided.
A backdoor used in a supply-chain attack against the sqgame gaming platform. On Android it runs from trojanized APKs, silently collects contacts, call logs, SMS, storage listings, device and network identifiers, geolocation, screenshots, audio, and selected file types, then uploads data via HTTPS to Zoho WorkDrive. On Windows it is installed after RokRAT is delivered through a malicious update.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.