A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
A North Korean-aligned APT group, ScarCruft (also known as APT37 or Reaper), conducted a supply-chain attack targeting a video game platform used by ethnic Koreans in the Yanbian region of China. The attackers injected a backdoor, dubbed BirdCall, into Windows and Android versions of games hosted on the platform, with the goal of espionage and data collection, including screenshots, voice recordings, and sensitive information. This attack highlights ScarCruft’s ongoing targeting of government and military organizations, as well as North Korean defectors, utilizing a newly developed Android version of their BirdCall backdoor.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data