Multiple reports say the North Korea-aligned hacking group ScarCruft (also associated with APT37) is using a supply-chain attack to spread a backdoor called BirdCall. The reports describe a compromise of a video game platform, where components are allegedly trojanized so that the malicious payload can be delivered to users who install or otherwise obtain software through the platform. One report specifically describes the deployment of an Android version of the BirdCall backdoor via the compromised platform, expanding on prior activity that had focused more heavily on Windows. Another report also describes the group’s use of the same supply-chain approach against gaming software distribution and indicates the campaign targets both Android and Windows environments, depending on the affected components. The backdoor is described as enabling unauthorized access and follow-on espionage. At least one source adds that the campaign is assessed to likely target ethnic Koreans living in China, although the broader scope of victims across devices and platforms is not fully established in the available summaries. Across the reporting, the central point is the use of a trusted software distribution channel to distribute the BirdCall malware as part of an espionage-oriented campaign.