North Korea-linked ScarCruft (APT37, also known as Reaper) compromised the sqgame[.]net gaming platform used by ethnic Koreans in China’s Yanbian region and used it to distribute the BirdCall backdoor in a supply-chain espionage campaign. ESET said the operation was likely active from late 2024, with the website compromised since at least November 2024, and assessed that the targets were likely North Korean defectors, refugees, and other people of interest to the regime in the Yanbian border area. The attackers appear to have tampered with the platform’s distribution infrastructure rather than stolen game source code, serving benign initial downloads and later malicious updates from the official site rather than Google Play.
The campaign affected both Android and Windows users. Trojanized Android game APKs delivered a newly documented mobile BirdCall variant capable of stealing contacts, SMS messages, call logs, documents, media files, and private keys, while also taking screenshots and recording ambient audio; researchers identified at least seven Android versions. On Windows, a malicious desktop client update used a trojanized mono.dll to fetch RokRAT, which then deployed the Windows BirdCall payload with broader surveillance features such as keystroke logging, clipboard theft, and shell execution. ESET said the malware blended command-and-control traffic into normal HTTPS activity and relied primarily on Zoho WorkDrive for exfiltration, while also using compromised South Korean websites to host payloads and configuration data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
ESET said it notified sqgame about the compromise in December 2025. At the time of publication, the researchers said they had not received a response from the company.
ESET assessed that ScarCruft's espionage campaign against sqgame, a gaming platform serving ethnic Koreans in China's Yanbian region, was likely active since late 2024. The attackers trojanized Android game APKs with BirdCall and also compromised the Windows update chain, likely targeting defectors, refugees, and related communities.
On May 5, 2026, ESET published research attributing a multiplatform supply-chain attack on sqgame to North Korea-aligned ScarCruft/APT37. The disclosure detailed Android BirdCall implants, a malicious Windows update chain, and likely espionage targeting of ethnic Koreans in Yanbian, including defectors and refugees.
ESET reported that the compromised sqgame platform's Windows desktop client update package had been delivering malicious components since at least November 2024. The Windows infection chain used a trojanized update to install RokRAT and then the Windows BirdCall payload.
ESET found at least seven Android BirdCall variants developed over several months, with reporting indicating the Android version was developed around October 2024. This marked an expansion of ScarCruft's tooling into Android surveillance malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
s2w.medium.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcewelivesecurity.com
Open sourcebankinfosecurity.com
Open sourcebsky.app
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.