BirdCall is a North Korea-linked backdoor associated with ScarCruft, also tracked as APT37 and Reaper. It has been documented as a Windows malware family since at least 2021 and later expanded to Android in a supply-chain espionage campaign targeting users of a gaming platform serving ethnic Koreans in China’s Yanbian region. The operation has been assessed as likely focused on surveillance of individuals of interest to the North Korean regime, including refugees and defectors.
On Windows, BirdCall is deployed through a multistage infection chain and has been observed delivered after RokRAT in a compromised software update workflow. Reported Windows capabilities include screenshot capture, keylogging, clipboard theft, file theft, credential theft, shell command execution, and broader data gathering. The Windows intrusion chain also used anti-analysis checks and downloader components before installing the backdoor.
The Android variant functions as a spyware-capable backdoor embedded into trojanized game packages and also has been reported masquerading as Zangi Messenger. It executes in the background while preserving the expected behavior of the host application. Documented Android capabilities include collecting contacts, SMS messages, call logs, device and network metadata, media files, documents, and private keys; taking screenshots; recording calls and ambient audio; and searching external storage for selected file types for exfiltration. Some variants recorded audio during evening hours. The Android implant has also been described as blending command-and-control traffic with normal traffic and using legitimate cloud services for command and control.
BirdCall is notable for ScarCruft’s transition from primarily Windows-focused tooling to a multiplatform surveillance capability. In the observed supply-chain campaign, Android users were infected through trojanized sideloaded game applications, while Windows users were infected through a malicious update package. The malware is best characterized as an espionage backdoor used for persistent surveillance, data theft, and post-compromise collection against politically and strategically relevant targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack BirdCall
34 distinct techniques documented for this family, organized by ATT&CK tactic.
ScarCruft compromised South Korean websites to host payloads and configurations. ScarCruft compromised the sqgame website to perform a supply-chain attack.
"victims typically downloaded the compromised games through a web browser on their devices and installed them directly, without going through the Google Play store."
After dropping the payload, it replaces itself with a clean copy to erase evidence.
BirdCall decrypts strings and loading chain components.
BirdCall’s loading chain has components encrypted with a computer-specific key.
BirdCall can scan a range of IPs and ports with an HTTP GET request.
It connects to cloud storage using hardcoded credentials and uploads data including RAM, IMEI, IP and MAC address, and geolocation.
"Through BirdCall, APT37 is able to collect contact information, SMS texts, call logs, media files and private keys... It also searches any shared external storage devices for specific file types."
"The backdoor, named BirdCall by the researchers, allowed APT37 to take screenshots..."
BirdCall can periodically collect files with certain extensions from local and removable drives.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BirdCall is the named malware discussed in the post. It is described as malware masquerading as Zangi Messenger, indicating a trojanized or impersonation-based delivery method. The post also associates it with ScarCruft.
Related Articles: NGate Android malware uses HandyPay NFC app to steal card data | ScarCruft hackers push BirdCall Android malware via game platform
A ScarCruft-linked backdoor/tool mentioned in connection with a supply-chain compromise of a gaming platform.
The content only references BirdCall by name as Android malware in a related article link; no further behavioral details are provided.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.