North Korean hackers target gamers with trojanized platform – here’s what to look out for



  • North Korean APT37 (ScarCruft) gang compromised a Yanbian gaming platform to deliver the BirdCall backdoor
  • On Windows, it enabled data theft and command execution; on Android, it exfiltrated contacts, messages, media, and ambient audio
  • The malware is actively maintained, with Android versions still hosted, targeting ethnic Koreans and defectors in China

North Korean state-sponsored threat actors are apparently targeting their compatriots living in (or moving through) China with advanced Android backdoors across gaming platforms.

A report from security researchers ESET claims to have seen an advanced supply-chain attack that probably began in late 2024. The threat actors, most likely ScarCruft (also known as APT37, or Reaper), managed to compromise SQgame, a multi-platform gaming service built specifically for the people of Yanbian.

https://cdn.mos.cms.futurecdn.net/eVgzzXmQMEyvzfYvAaAMrX-1919-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img