Multiple reports say the North Korea-aligned hacking group ScarCruft (also associated with APT37) is using a supply-chain attack to spread a backdoor called BirdCall. The reports describe a compromise of a video game platform, where components are allegedly trojanized so that the malicious payload can be delivered to users who install or otherwise obtain software through the platform. One report specifically describes the deployment of an Android version of the BirdCall backdoor via the compromised platform, expanding on prior activity that had focused more heavily on Windows. Another report also describes the group’s use of the same supply-chain approach against gaming software distribution and indicates the campaign targets both Android and Windows environments, depending on the affected components. The backdoor is described as enabling unauthorized access and follow-on espionage. At least one source adds that the campaign is assessed to likely target ethnic Koreans living in China, although the broader scope of victims across devices and platforms is not fully established in the available summaries. Across the reporting, the central point is the use of a trusted software distribution channel to distribute the BirdCall malware as part of an espionage-oriented campaign.
ScarCruft compromises gaming platform to deliver BirdCall backdoor malware
Multiple reports say the North Korea-aligned hacking group ScarCruft (also associated with APT37) is using a supply-chain attack to spread a backdoor called BirdCall. The reports describe a compromise...
- ScarCruft/APT37 is linked to the campaign described.
- The group compromises a video game platform as part of a supply-chain attack.
- The attack delivers a backdoor named BirdCall.
- The reported impact includes Android delivery, with prior versions also targeting Windows.
- The campaign is assessed to target ethnic Koreans residing in China.
The North Korea-aligned state-sponsored hacking group known as ScarCruft has compromised a video game platform in a supply chain espionage attack, trojanizing its components with a backdoor called BirdCallto likely target ethnic Koreans residing in China. While prior versions of the backdoor have primarily targeted Windows users only, the supply chain attack is assessed to have enabled the
3 months agoThe North Korean hacker group APT37 has been delivering an Android version of a backdoor called BirdCall in a supply-chain attack through a video game platform. [...]
3 months agoBathla developer collapses into administration, leaving unfinished housing projects
A major property developer, Bathla, collapses into administration on Tuesday, leaving multiple housing developments inco...
Apple sets Sept. 9 iPhone launch event as John Ternus begins his CEO tenure
Apple is set to hold a major product launch event on September 9, where it is expected to unveil its next iPhone lineup....
Dolly Parton’s “Jolene” returns to No. 1 on Apple Music charts over 50 years later
Dolly Parton’s 1973 song “Jolene” reaches No. 1 on Apple Music’s Top 100 USA chart more than 50 years after its release....