{"id":17118,"date":"2026-07-26T23:14:03","date_gmt":"2026-07-26T23:14:03","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17118"},"modified":"2026-07-26T23:14:03","modified_gmt":"2026-07-26T23:14:03","slug":"scarcruft-compromises-gaming-platform-in-a-supply-chain-assault","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17118","title":{"rendered":"ScarCruft compromises gaming platform in a supply-chain assault"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>ESET researchers uncovered a multiplatform supply-chain assault by North Korea-aligned APT group ScarCruft, focusing on the Yanbian area in China \u2013 residence to ethnic Koreans and a crossing level for North Korean refugees and defectors. Within the assault, in all probability ongoing since late 2024, ScarCruft compromised Home windows and Android elements of a online game platform devoted to Yanbian-themed video games, trojanizing them with a backdoor.<\/p>\n<p>The backdoor, named BirdCall by ESET, was initially recognized to focus on Home windows solely; the Android model was found as a part of this supply-chain assault. On this blogpost, we offer an outline of the assault, and the primary public evaluation of the Android backdoor.<\/p>\n<blockquote>\n<p><strong>Key factors of this blogpost:<\/strong><\/p>\n<ul>\n<li>North Korea-aligned APT group ScarCruft compromised a online game platform utilized by ethnic Koreans dwelling within the Yanbian area in China.<\/li>\n<li>The gaming platform\u2019s Home windows shopper was compromised by a malicious replace resulting in the RokRAT backdoor, which deployed the extra subtle BirdCall backdoor.<\/li>\n<li>Android video games out there on the gaming platform had been trojanized to comprise the Android model of the BirdCall backdoor \u2013 a brand new device in ScarCruft\u2019s arsenal.<\/li>\n<li>The objective of the marketing campaign is espionage, with the backdoor able to amassing private knowledge and paperwork, taking screenshots, and making voice recordings.<\/li>\n<\/ul>\n<\/blockquote>\n<h2>Scarcruft profile<\/h2>\n<p>ScarCruft, often known as APT37 or Reaper, has been working since not less than 2012 and is <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/groups\/G0067\/\" target=\"_blank\" rel=\"noopener\">suspected to be a North Korean espionage group<\/a>. It primarily focuses on South Korea, however different Asian nations have additionally been focused. ScarCruft appears to be  primarily in authorities and navy organizations, and corporations in varied industries linked to the pursuits of North Korea. The group additionally targets North Korean defectors, with the newest such exercise introduced on this blogpost.<\/p>\n<h2>BirdCall backdoor<\/h2>\n<h3>Home windows model<\/h3>\n<p>BirdCall is a Home windows backdoor written in C++ that we found in 2021 and attributed to ScarCruft as a part of the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/\" target=\"_blank\" rel=\"noopener\">ESET Menace Intelligence<\/a> reporting.<\/p>\n<p>The backdoor has a variety of spying capabilities, together with taking screenshots, logging keystrokes and clipboard content material, stealing credentials and recordsdata, and executing shell instructions. For C&amp;C functions, the backdoor makes use of official cloud storage companies, comparable to Dropbox or pCloud, or compromised web sites. BirdCall is normally deployed in a multistage loading chain, beginning with a Ruby or Python script, and containing elements encrypted utilizing a computer-specific key. The preliminary model of BirdCall was publicly described by South Korean distributors in 2021 as a complicated model of RokRAT (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/medium.com\/s2wblog\/matryoshka-variant-of-rokrat-apt37-scarcruft-69774ea7bf48\" target=\"_blank\" rel=\"noopener\">S2W<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.ahnlab.com\/ko\/contents\/content-center\/30164\" target=\"_blank\" rel=\"noopener\">AhnLab<\/a>).<\/p>\n<h3>Android model<\/h3>\n<p>The Android model of BirdCall, found within the assault that we describe on this blogpost, implements a subset of the instructions and capabilities of the Home windows backdoor \u2013 it collects contacts, SMS messages, name logs, paperwork, media recordsdata, and personal keys. It could additionally take screenshots and report surrounding audio.<\/p>\n<p>Primarily based on our analysis, Android BirdCall was actively developed over a span of a number of months. We recognized seven variations, starting from model 1.0 (created roughly in October 2024) to model 2.0 (created roughly in June 2025).<\/p>\n<h2>Discovery<\/h2>\n<p>Our investigation began with a suspicious APK file discovered on VirusTotal. Upon preliminary evaluation, we decided that the APK is malicious and incorporates a backdoor.<\/p>\n<p>Curiously, the APK turned out to be a trojanized card recreation known as \u5ef6\u8fb9\u7ea2\u5341 (machine translation: Yanbian Crimson Ten), which we traced to its official web site, <span style=\"font-family: courier new, courier, monospace;\">https:\/\/www.sqgame[.]web<\/span>. sqgame is a gaming platform tailor-made for the individuals of Yanbian and hosts conventional Yanbian video games for Home windows, Android, and iOS. The gamers can compete in card and board video games (see Determine\u00a01) with buddies or be part of organized tournaments.<\/p>\n<figure><img decoding=\"async\" title=\"Figure 1. Yanbian Red Ten game\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/04-26\/scarcruft\/figure-1.jpg\" alt=\"Figure 1. Yanbian Red Ten game\" width=\"\" height=\"\"\/><figcaption><em>Determine 1. Yanbian Crimson Ten recreation<\/em><\/figcaption><\/figure>\n<p>Surprisingly, the APK out there for obtain on the official web site is similar because the APK we initially discovered on VirusTotal. Furthermore, a second Android recreation (\u65b0\u753b\u56fe, machine translation: New Drawing) out there for obtain from sqgame was additionally trojanized with the identical backdoor. Additional evaluation revealed that the backdoor is an Android port of the ScarCruft group\u2019s BirdCall backdoor.<\/p>\n<p>The Home windows desktop shopper hyperlink on the sqgame web site results in a few-years-old installer that seems to be clear. It does obtain updates as soon as put in, however we didn&#8217;t determine any malicious code there throughout our evaluation.<\/p>\n<p>Investigating additional in ESET telemetry, we recognized a trojanized <span style=\"font-family: courier new, courier, monospace;\">mono.dll<\/span> library, originating from an replace package deal for the desktop shopper. ESET telemetry exhibits that this replace package deal had been malicious since not less than November 2024, for an unknown interval. On the time of writing, this replace package deal was not malicious.<\/p>\n<p>We additionally checked the iOS recreation out there on the sqgame web site and didn\u2019t discover any malicious code. We expect that ScarCruft skipped this platform, for the reason that trojanization and supply of the app can be far more tough in comparison with different platforms, presumably working into Apple\u2019s overview course of.<\/p>\n<h2>Victimology<\/h2>\n<p>For the reason that web site compromised on this assault is devoted to the individuals of Yanbian and their conventional video games, we infer that the first targets are ethnic Koreans dwelling in Yanbian. Yanbian Korean Autonomous Prefecture is a area in China that borders North Korea and is residence to the biggest ethnic Korean neighborhood exterior Korea.<\/p>\n<p>On this context, we consider that it&#8217;s possible that the assault was aimed toward amassing info on people primarily based in (or originating from) the Yanbian area and deemed of curiosity to the North Korean regime \u2013 most certainly refugees or defectors.<\/p>\n<h2>Assault overview<\/h2>\n<h3>Android<\/h3>\n<p>Two of the Android video games out there on the sqgame web site had been discovered to be trojanized to comprise the BirdCall backdoor. The obtain web page out there at <span style=\"font-family: courier new, courier, monospace;\">https:\/\/www.sqgame[.]web\/video games\/gamedownload.aspx<\/span> is proven in Determine\u00a02, with obtain buttons for the 2 trojanized video games highlighted in crimson. The third out there Android recreation was clear on the time of our evaluation.<\/p>\n<figure><img decoding=\"async\" title=\"Figure 2. Download page leading to trojanized games\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/04-26\/scarcruft\/figure-2.png\" alt=\"Figure 2. Download page leading to trojanized games\" width=\"\" height=\"\"\/><figcaption><em>Determine 2. Obtain web page resulting in trojanized video games<\/em><\/figcaption><\/figure>\n<p>We discovered proof that the victims downloaded the trojanized video games by way of an online browser on their gadgets and doubtless put in them deliberately. We&#8217;ve not discovered some other APK areas. We additionally haven&#8217;t discovered the malicious APKs on the official Google Play retailer.<\/p>\n<p>We had been unable to find out when the web site was first compromised and the supply-chain assault began. Nevertheless, primarily based on our evaluation of the deployed malware, we estimate that it occurred in late 2024.<\/p>\n<p>Desk\u00a01 exhibits the internet hosting URLs of the 2 trojanized APK recordsdata, together with the hashes of recordsdata served on the time of discovery. On the time of writing of this blogpost, the malicious recordsdata had been nonetheless up on the sqgame web site. We notified sqgame of the compromise in December 2025, however haven\u2019t acquired a response.<\/p>\n<p style=\"text-align: center;\"><em>Desk\u00a01. Malicious samples<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td style=\"width: 72px;\" width=\"68\"><strong>Time of discovery<\/strong><\/td>\n<td style=\"width: 216px;\" nowrap=\"nowrap\" width=\"234\"><strong>URL<\/strong><\/td>\n<td style=\"width: 368px;\" nowrap=\"nowrap\" width=\"151\"><strong>SHA\u20111<\/strong><\/td>\n<td style=\"width: 289px;\" nowrap=\"nowrap\" width=\"189\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 72px;\" nowrap=\"nowrap\" width=\"68\">2025-10<\/td>\n<td style=\"width: 216px;\" nowrap=\"nowrap\" width=\"234\"><span style=\"font-family: courier new, courier, monospace;\">http:\/\/sqgame.com<wbr\/>[.]cn\/ybht.apk<\/span><\/td>\n<td style=\"width: 368px;\" nowrap=\"nowrap\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">03E3ECE9F48CF4104AAF<wbr\/>C535790CA2FB3C6B26CF<\/span><\/td>\n<td style=\"width: 289px;\" nowrap=\"nowrap\" width=\"189\">Trojanized recreation with the BirdCall <wbr\/>backdoor.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 72px;\" nowrap=\"nowrap\" width=\"68\">2025-10<\/td>\n<td style=\"width: 216px;\" nowrap=\"nowrap\" width=\"234\"><span style=\"font-family: courier new, courier, monospace;\">http:\/\/sqgame.com<wbr\/>[.]cn\/sqybhs.apk<\/span><\/td>\n<td style=\"width: 368px;\" nowrap=\"nowrap\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">FC0C691DB7E2D2BD3B0B<wbr\/>4C1E24D18DF72168B7D9<\/span><\/td>\n<td style=\"width: 289px;\" nowrap=\"nowrap\" width=\"189\">Trojanized recreation with the BirdCall <wbr\/>backdoor.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Home windows<\/h3>\n<p>Whereas the Home windows desktop shopper out there on the sqgame web site didn&#8217;t comprise malicious code after we analyzed it, we later recognized a trojanized <span style=\"font-family: courier new, courier, monospace;\">mono.dll<\/span> library, originating from an replace package deal of the desktop shopper hosted on the URL <span style=\"font-family: courier new, courier, monospace;\">http:\/\/xiazai.sqgame.com[.]cn\/relationship\/20240429.zip<\/span>. ESET telemetry exhibits that this replace package deal had been malicious since not less than November 2024, for an unknown interval \u2013 however on the time of writing, this replace package deal was not malicious.<\/p>\n<p>ScarCruft took a clear mono library and patched it with further code and knowledge, containing a downloader. The downloader first checks working processes for evaluation instruments and digital machine environments and doesn&#8217;t proceed if any are discovered. In any other case, it seems for the method of the sqgame shopper and constructs a path to the mono library in its set up folder.<\/p>\n<p>Subsequent, it downloads and executes shellcode, which contained the RokRAT backdoor on the time of discovery. Lastly, the downloader terminates the shopper course of and downloads the unique clear model of the mono library, changing the trojanized one within the put in shopper folder. Each the payload and clear mono library are downloaded from official South Korean web sites that had been compromised for this function \u2013 a typical TTP of ScarCruft.<\/p>\n<p>In line with our telemetry, the RokRAT backdoor was subsequently used to obtain and set up the BirdCall backdoor on the victimized machines.<\/p>\n<h2>Android BirdCall evaluation<\/h2>\n<p>On this part, we offer a technical evaluation of the Android BirdCall backdoor \u2013 an Android port of the eponymous Home windows backdoor written in C++. Internally, the backdoor is known as <span style=\"font-family: courier new, courier, monospace;\">zhuagou<\/span>, which may be translated (from Chinese language) as \u201ccatching canine\u201d.<\/p>\n<h3>Trojanized Android video games<\/h3>\n<p>Android BirdCall is distributed by way of trojanized Android video games. Within the assault described on this blogpost, we consider that ScarCruft didn&#8217;t acquire entry to the sport\u2019s supply code, solely to the sqgame web site or internet server, and as a substitute took the unique recreation APKs and recompiled or repackaged them with malicious code added.<\/p>\n<p>Within the trojanized APKs, the <span style=\"font-family: courier new, courier, monospace;\">AndroidManifest.xml<\/span> entry level exercise is modified and factors to the added malicious code \u2013 which, after beginning the backdoor, executes the unique entry exercise of the sport.<\/p>\n<p>Within the analyzed samples, the modified entry level exercise was both <span style=\"font-family: courier new, courier, monospace;\">com.instance.zhuagou.SplashScreen<\/span> or <span style=\"font-family: courier new, courier, monospace;\">com.mob.util.MobSs<\/span> (within the newest pattern). The modifications to <span style=\"font-family: courier new, courier, monospace;\">AndroidManifest.xml<\/span> additionally embrace new exercise and repair definitions for the backdoor, in addition to extra permissions required for its operation. A comparability of packages within the unique recreation and its trojanized model is proven in Determine\u00a03.<\/p>\n<figure><img decoding=\"async\" title=\"Figure 3. Package tree of the legitimate game (left) and its trojanized version (right)\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/04-26\/scarcruft\/figure-3.png\" alt=\"Figure 3. Package tree of the legitimate game (left) and its trojanized version (right)\" width=\"\" height=\"\"\/><figcaption><em>Determine 3. Bundle tree of the official recreation (left) and its trojanized model (proper)<\/em><\/figcaption><\/figure>\n<p>For the reason that Android BirdCall backdoor is part of a trojanized Android app put in on the system, it doesn&#8217;t mechanically begin after set up or a tool reboot; as a substitute, it depends on person execution.<\/p>\n<h3>Configuration<\/h3>\n<p>Android BirdCall incorporates a default configuration, which is initialized on the primary run. The configuration makes use of JSON format and is endured in a file. Subsequent runs load the present configuration file, and the configuration may be modified by way of backdoor instructions. An instance of a formatted configuration is proven in Determine\u00a04.<code\/><\/p>\n<pre class=\"language-markup\"><code>{\n    \"bi\": \"E823D451D636D0A0\",\n    \"skey\": \"A8FE823D451D636D0A0366C0629EF5C3##@(()(#@\",\n    \"si\": \"20251105141404\",\n    \"rft\": 20000,\n    \"fst\": true,\n    \"kill\": false,\n    \"log\": true,\n    \"ctm\": 10000,\n    \"scr\": false,\n    \"rec\": false,\n    \"cmd\": 0,\n    \"knowledge\": 1,\n    \"bd_version\": 37,\n    \"extentions\": \".jpg;.doc;.docx;.xls;.xlsx;.ppt;.pptx;.txt;.hwp;.pdf;.m4a;.p12;\",\n    \"cloud\": [\n        {\n            \"ct\": 9,\n            \"idx\": 28,\n            \"cid\": \"1000.2IGB56IS1FHQ1V332R[redacted]\",\n            \"cst\": \"fa7ec5c8b050[redacted]\",\n            \"rt\": \"1000.a7fc479e[redacted]\",\n            \"at\": \"empty\",\n            \"fid\": \"8mwe5bbc0a2759839401f813968808a2f36a6\",\n            \"dm\": \"\",\n            \"use\": 0\n        },\n        [redacted]\n    ]\n}<\/code><\/pre>\n<pre><code\/><\/pre>\n<p><em>Determine\u00a04. Android BirdCall configuration instance<\/em><\/p>\n<p>The <span style=\"font-family: courier new, courier, monospace;\">bd_version<\/span> configuration entry encodes the model of the backdoor, saved as <span style=\"font-family: courier new, courier, monospace;\">MAJOR &lt;&lt; 5 | MINOR<\/span>, so worth 37 is the same as model 1.5.<\/p>\n<p>The endured configuration file is saved within the knowledge listing of the app and has a device-specific path. Moreover, in the course of the configuration initialization, the default configuration of cloud storage drives hardcoded within the pattern may be overridden by an exterior supply. If out there, the backdoor downloads a JPG picture that incorporates an encrypted cloud configuration embedded in its overlay. The picture is normally hosted on a compromised South Korean web site.<\/p>\n<h3>C&amp;C communication<\/h3>\n<p>Android BirdCall makes use of cloud storage drives for C&amp;C communication, just like the Home windows model. Within the analyzed samples, three cloud suppliers are supported: pCloud, Yandex Disk, and Zoho WorkDrive, though solely Zoho WorkDrive is used. The backdoor communicates by way of HTTPS, sending requests to API endpoints of the respective supplier utilizing the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/square.github.io\/okhttp\/\" target=\"_blank\" rel=\"noopener\">okhttp3<\/a> library.<\/p>\n<p>Throughout our analysis, we noticed 12 Zoho WorkDrive drives utilized by the Android BirdCall backdoor for C&amp;C functions. Particulars of the related accounts are proven in Desk\u00a02.<\/p>\n<p style=\"text-align: center;\"><em>Desk\u00a02. Android BirdCall Zoho WorkDrive accounts<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"170\"><strong>client_id<\/strong><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><strong>display_name<\/strong><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><strong>e mail<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.AJUEYDUIQQ5G<wbr\/>CLFA68[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">tomasalfred37<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">tomasalfred37@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.INXKBHQ3698C<wbr\/>K42YA2[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">kalimaxim279<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">kalimaxim279@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.FYRJ46E75TUY<wbr\/>BWYV5J[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">Smith Bentley<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">smithbentley0617@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.8QU6D2LJZ3RC<wbr\/>GLZWF2[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">Mic haelLarrow19<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">michaellarrow19@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.NT1QEE7V73IH<wbr\/>NZP5YT[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">dsf sdf<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">amandakurth94@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.SKXUYYKYL06F<wbr\/>Q2NW82[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">dsf sdf<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">rexmedina89@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.7BMBOS8GV1ZR<wbr\/>6AWEI2[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">dsf dsf<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">alishaross751@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.V0J0QN7SJ2N7<wbr\/>V6IZVE[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">sdf sdf<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">jamesdeeds385@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.2IGB56IS1FHQ<wbr\/>1V332R[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">asdf sdaf<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">joyceluke505@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.W4V2XMB83C6V<wbr\/>FC7DGZ[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">dfsd sdf<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">marjoriemiller280@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.LIUBF67S89H0<wbr\/>IZEBHE[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">Invoice Jackson<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">teresadaniels200@zohomail[.]com<\/span><\/td>\n<\/tr>\n<tr>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">1000.8BLOFSFU4WOF<wbr\/>Y9HB4A[redacted]<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"170\"><span style=\"font-family: courier new, courier, monospace;\">Zoe Jack<\/span><\/td>\n<td nowrap=\"nowrap\" width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">michaelgiesen62@zohomail[.]com<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Capabilities<\/h3>\n<p>Android BirdCall options an replace mechanism: a more recent model may be loaded from an replace file, which is predicted to be within the type of an APK within the app knowledge listing, and its obtain is triggered by way of the command <span style=\"font-family: courier new, courier, monospace;\">MP_SEND_FILE<\/span>.<\/p>\n<p>After the non-obligatory replace process, the unique recreation exercise is began, so as to not elevate suspicion. Then the backdoor checks and waits for an web connection, earlier than continuing to its essential operation.<\/p>\n<h4>Information assortment<\/h4>\n<p>On the primary run, the backdoor collects a full listing itemizing of the system\u2019s main <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/developer.android.com\/reference\/android\/os\/Environment.html#getExternalStorageDirectory()\" target=\"_blank\" rel=\"noopener\">shared exterior storage<\/a>, and person knowledge consisting of contact record, name log, and SMS messages.<\/p>\n<p>The backdoor periodically checks in with the C&amp;C and uploads primary info, which consists of:<\/p>\n<ul>\n<li>identifier values from configuration and present time,<\/li>\n<li>battery temperature, RAM and storage info, cloud configuration, backdoor model, and file extensions of curiosity,<\/li>\n<li>IP geolocation info from <span style=\"font-family: courier new, courier, monospace;\">https:\/\/ipinfo[.]io\/json<\/span>, and<\/li>\n<li>on the primary run, extra details about the system, community, and the appliance is included:\n<p style=\"margin-top: 0.8em; margin-bottom: 0; display: flex; align-items: flex-start; gap: 0.6em;\"><span style=\"color: #00a0a0; font-size: 1em; line-height: 1em; flex-shrink: 0;\">\u25cb<\/span> <span style=\"margin: 0;\">model, mannequin, OS, kernel, and rooted standing,<\/span><\/p>\n<p style=\"margin-top: 0.2em; margin-bottom: 0; display: flex; align-items: flex-start; gap: 0.6em;\"><span style=\"color: #00a0a0; font-size: 1em; line-height: 1em; flex-shrink: 0;\">\u25cb<\/span> <span style=\"margin: 0;\">IMEI quantity, IP tackle, MAC tackle, and community sort, and <\/span><\/p>\n<p style=\"margin-top: 0.2em; margin-bottom: 0; display: flex; align-items: flex-start; gap: 0.6em;\"><span style=\"color: #00a0a0; font-size: 1em; line-height: 1em; flex-shrink: 0;\">\u25cb<\/span> <span style=\"margin: 0;\">utility package deal and permissions.<\/span><\/p>\n<\/li>\n<\/ul>\n<p>The backdoor can periodically take screenshots (<span style=\"font-family: courier new, courier, monospace;\">scr<\/span> flag). In some variations, we noticed the strategy of enjoying a silent MP3 file in a loop whereas taking screenshots, which is used to forestall the trojanized app from being suspended whereas working within the background.<\/p>\n<p>In among the variations, the backdoor can report audio by way of the microphone and listen in on the environment of the compromised system. Unusually, even when the recording is enabled (<span style=\"font-family: courier new, courier, monospace;\">rec<\/span> flag), it&#8217;s restricted to a three-hour time interval within the night, from 7 pm to 10 pm native time.<\/p>\n<p>The backdoor periodically searches the shared exterior storage for recordsdata with extensions of curiosity (<span style=\"font-family: courier new, courier, monospace;\">extentions<\/span>) and phases them for exfiltration. Within the samples we analyzed, exfiltration was aimed toward media recordsdata, paperwork, and personal keys: <span style=\"font-family: courier new, courier, monospace;\">.jpg<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.doc<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.docx<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.xls<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.xlsx<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.ppt<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.pptx<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.txt<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.hwp<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.pdf<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.m4a<\/span>, and <span style=\"font-family: courier new, courier, monospace;\">.p12<\/span>.<\/p>\n<h4>Instructions<\/h4>\n<p>Android BirdCall periodically checks the cloud storage drive for instructions issued for the sufferer. Decrypted instructions begin with the magic DWORD <span style=\"font-family: courier new, courier, monospace;\">0x2A7B4C33<\/span>, and this worth matches the Home windows model of BirdCall. The instructions have zero or extra parameters, relying on their sort. Desk\u00a03 exhibits an outline of the supported instructions with their descriptions for each platforms.<\/p>\n<p>The Android model of the backdoor implements solely a subset of instructions out there within the Home windows model.<\/p>\n<p style=\"text-align: center;\"><em>Desk\u00a03. BirdCall backdoor instructions<\/em><\/p>\n<table style=\"width: 783px;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<thead style=\"font-size: 12.5px;\">\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><strong>Sort<\/strong><\/td>\n<td style=\"width: 246px;\" nowrap=\"nowrap\"><strong>Identify<\/strong><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\"><strong>Android description<\/strong><\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\"><strong>Home windows description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x48<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_SET_FILESEARCH_EXTENTION<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 481px;\" colspan=\"2\">Units file extensions of curiosity within the configuration.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x49<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_SET_THREADS<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">Toggles screenshot taking and voice recording.<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Contains extra capabilities comparable to clipboard stealing and keylogging.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x4A<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_SET_CLOUD<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 481px;\" colspan=\"2\">Units cloud API credentials within the configuration.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x4B<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_SET_REGISTER_FILE_CONTROL<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">N\/A<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Modifies filter used throughout file search.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x4C<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_SET_MODE<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">Toggles assortment of the backdoor execution logs.<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Toggles varied collection-related flags.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x4D<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_ACTION_KILLME<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">Disables the backdoor. The unique recreation continues working.<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Uninstalls the backdoor and exits.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x4E<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_ACTION_KILLPROCESS<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">N\/A<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Makes use of the taskkill utility to kill a course of.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x4F<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_ACTION_FILE_OR_DIRECTORY<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">Helps add of a specified file or listing.<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Helps a number of file and listing operations: delete, rename, open, and add.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x50<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_ACTION_DOWNLOAD_COMMAND<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">N\/A<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Downloads and executes instructions from a URL or cloud drive.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x51<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_ACTION_RESET_WORKDIRECTORIES<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">N\/A<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Can delete working directories utilized by the backdoor.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x52<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_ACTION_EXECUTE_SIMPLE_COMMAND<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">N\/A<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Can restart the backdoor and execute a command by way of <span style=\"font-family: courier new, courier, monospace;\">cmd.exe<\/span>.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x53<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_ACTIONS_MORE<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">N\/A<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Can carry out three operations:<br \/>\u00b7 Delete endured configuration.<br \/>\u00b7 Allow macros in Phrase (Microsoft and Hancom Workplace).<br \/>\u00b7 Restart the backdoor.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x54<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_ACTION_SHELL<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">N\/A<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Begins shell (primarily based on <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gitlab.winehq.org\/wine\/wine\/-\/tree\/master\/programs\/cmd\"><em>WCMD<\/em><\/a>).<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x55<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_ACTION_WEBSCAN<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">N\/A<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Performs HTTP scan of specified hosts\/ports.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x56<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_GET_DATA<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">Can get hold of:<br \/>\u00b7 contacts, name logs, and SMS messages,<br \/>\u00b7 full listing itemizing of the first shared exterior storage, and<br \/>\u00b7 primary info.<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Can get hold of:<br \/>\u00b7 backdoor configuration and varied system info,<br \/>\u00b7 credentials from browsers and different software program,<br \/>\u00b7 recordsdata from IM apps \u2013 KakaoTalk, WeChat, and Sign,<br \/>\u00b7 digicam images, and<br \/>\u00b7 listing itemizing.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x57<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_GET_TREES<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 481px;\" colspan=\"2\">Retrieves listing itemizing.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x59<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_SEND_FILE<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">Helps backdoor updating.<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Helps dropping of a file to a specified location, dropping and execution of extra executables, and updating of the backdoor.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x5A<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_SEND_SHELL<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">N\/A<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Executes shell instructions.<\/td>\n<\/tr>\n<tr>\n<td style=\"font-size: 12.5px; width: 46px;\"><span style=\"font-family: courier new, courier, monospace;\">0x5C<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 246px;\"><span style=\"font-family: courier new, courier, monospace;\">MP_SET_PROXY<\/span><\/td>\n<td style=\"font-size: 12.5px; width: 227.062px;\">N\/A<\/td>\n<td style=\"font-size: 12.5px; width: 253.938px;\">Connects to a specified <span style=\"font-family: courier new, courier, monospace;\"><ip>:<port\/><\/ip><\/span> and forwards visitors from\/to the C&amp;C server, performing as a proxy.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>A dump containing the Home windows model of BirdCall that intently resembles the one we noticed on this assault and options all of the instructions listed above may be discovered on VirusTotal with SHA\u20111 <span style=\"font-family: courier new, courier, monospace;\">B06110E0FEB7592872E380B7E3B8F77D80DD1108<\/span>. The pattern was uploaded from China on July 15<sup>th<\/sup>, 2024.<\/p>\n<h2>Conclusion<\/h2>\n<p>We&#8217;ve uncovered a multiplatform supply-chain assault focusing on the Yanbian area by a compromised online game platform. Analyzing the trojanized Android video games on the platform, we found a brand new device in ScarCruft\u2019s arsenal \u2013 an Android model of the group\u2019s BirdCall backdoor. The Android backdoor has seen energetic growth, and supplies surveillance capabilities, comparable to assortment of non-public knowledge and paperwork, taking screenshots, and making voice recordings.<\/p>\n<blockquote>\n<div><em>For any inquiries about our analysis printed on WeLiveSecurity, please contact us at <a rel=\"nofollow\" target=\"_blank\" style=\"background-color: #f4f4f4;\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack\/mailto:threatintel@eset.com?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=eset-research&amp;utm_term=en\">threatintel@eset.com<\/a>.\u00a0<\/em><\/div>\n<div><em>ESET Analysis provides non-public APT intelligence experiences and knowledge feeds. For any inquiries about this service, go to the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\">ESET Menace Intelligence<\/a> web page.<\/em><\/div>\n<\/blockquote>\n<h2>IoCs<\/h2>\n<p>A complete record of indicators of compromise (IoCs) and samples may be present in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/eset\/malware-ioc\/tree\/master\/scarcruft\" target=\"_blank\" rel=\"noopener\">our GitHub repository<\/a>.<\/p>\n<h3>Information<\/h3>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"187\"><strong>SHA-1<\/strong><\/td>\n<td width=\"107\"><strong>Filename<\/strong><\/td>\n<td width=\"147\"><strong>Detection<\/strong><\/td>\n<td width=\"161\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"187\"><span style=\"font-family: courier new, courier, monospace;\">01A33066FBC6253304C9<wbr\/>2760916329ABD50C3191<\/span><\/td>\n<td width=\"107\"><span style=\"font-family: courier new, courier, monospace;\">sqybhs.apk<\/span><\/td>\n<td width=\"147\">Android\/Spy.Agent.EXM<\/td>\n<td width=\"161\">Trojanized recreation with Android BirdCall model 2.0.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><span style=\"font-family: courier new, courier, monospace;\">03E3ECE9F48CF4104AAF<wbr\/>C535790CA2FB3C6B26CF<\/span><\/td>\n<td width=\"107\"><span style=\"font-family: courier new, courier, monospace;\">ybht.apk<\/span><\/td>\n<td width=\"147\">Android\/Spy.Agent.EGE<\/td>\n<td width=\"161\">Trojanized recreation with Android BirdCall model 1.3.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><span style=\"font-family: courier new, courier, monospace;\">2B81F78EC4C3F8D6CF8F<wbr\/>677D141C5D13C35333AF<\/span><\/td>\n<td width=\"107\"><span style=\"font-family: courier new, courier, monospace;\">sqybhs.apk<\/span><\/td>\n<td width=\"147\">Android\/Spy.Agent.EGE<\/td>\n<td width=\"161\">Trojanized recreation with Android BirdCall model 1.5.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><span style=\"font-family: courier new, courier, monospace;\">59A9B9D47AE36411B277<wbr\/>544F25AD2CC955D8DD2C<\/span><\/td>\n<td width=\"107\"><span style=\"font-family: courier new, courier, monospace;\">ybht.apk<\/span><\/td>\n<td width=\"147\">Android\/Spy.Agent.EGE<\/td>\n<td width=\"161\">Trojanized recreation with Android BirdCall model 1.0.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><span style=\"font-family: courier new, courier, monospace;\">7356D7868C81499FB4E7<wbr\/>20F7C9530E5763B4C1D0<\/span><\/td>\n<td width=\"107\"><span style=\"font-family: courier new, courier, monospace;\">sqybhs.apk<\/span><\/td>\n<td width=\"147\">Android\/Spy.Agent.EGE<\/td>\n<td width=\"161\">Trojanized recreation with Android BirdCall model 1.0.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><span style=\"font-family: courier new, courier, monospace;\">FC0C691DB7E2D2BD3B0B<wbr\/>4C1E24D18DF72168B7D9<\/span><\/td>\n<td width=\"107\"><span style=\"font-family: courier new, courier, monospace;\">sqybhs.apk<\/span><\/td>\n<td width=\"147\">Android\/Spy.Agent.EGE<\/td>\n<td width=\"161\">Trojanized recreation with Android BirdCall model 1.5.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><span style=\"font-family: courier new, courier, monospace;\">95BDB94F6767A3CCE6D9<wbr\/>2363BBF5BC84B786BDB0<\/span><\/td>\n<td width=\"107\"><span style=\"font-family: courier new, courier, monospace;\">mono.dll<\/span><\/td>\n<td width=\"147\">Win32\/TrojanDownloader<wbr\/>.Agent.ILQ<\/td>\n<td width=\"161\">Trojanized mono library.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><span style=\"font-family: courier new, courier, monospace;\">409C5ACAED587F62F7E2<wbr\/>3DA47F72C4D9EC3144D9<\/span><\/td>\n<td width=\"107\">N\/A<\/td>\n<td width=\"147\">Win32\/TrojanDownloader<wbr\/>.Agent.ILQ<\/td>\n<td width=\"161\">Downloader resulting in the RokRAT backdoor.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><span style=\"font-family: courier new, courier, monospace;\">B06110E0FEB7592872E3<wbr\/>80B7E3B8F77D80DD1108<\/span><\/td>\n<td width=\"107\">N\/A<\/td>\n<td width=\"147\">Win64\/Agent.EGN<\/td>\n<td width=\"161\">Publicly out there dump of Home windows BirdCall backdoor.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Community<\/h3>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"123\"><strong>IP<\/strong><\/td>\n<td width=\"123\"><strong>Area<\/strong><\/td>\n<td width=\"132\"><strong>Internet hosting supplier<\/strong><\/td>\n<td width=\"95\"><strong>First seen<\/strong><\/td>\n<td width=\"170\"><strong>Particulars<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">39.106.249[.]68<\/span><\/td>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">sqgame.com[.]cn<\/span><\/td>\n<td width=\"132\">Hangzhou Alibaba Promoting Co.,Ltd.<\/td>\n<td width=\"95\">2024\u201106\u201101<\/td>\n<td width=\"170\">Compromised sqgame website internet hosting trojanized video games and malicious updates.<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">211.239.117[.]117<\/span><\/td>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">1980food.co[.]kr<\/span><\/td>\n<td width=\"132\">Hostway IDC<\/td>\n<td width=\"95\">2025\u201103\u201107<\/td>\n<td width=\"170\">Compromised South Korean website used to host Android BirdCall configuration.<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">114.108.128[.]157<\/span><\/td>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">inodea[.]com<\/span><\/td>\n<td width=\"132\">LG DACOM Company<\/td>\n<td width=\"95\">2025\u201107\u201103<\/td>\n<td width=\"170\">Compromised South Korean website used to host Android BirdCall configuration.<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">221.143.43[.]214<\/span><\/td>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">www.lawwell.co[.]kr<\/span><\/td>\n<td width=\"132\">SK Broadband Co Ltd<\/td>\n<td width=\"95\">2024\u201111\u201104<\/td>\n<td width=\"170\">Compromised South Korean website used to host shellcode and clear mono library.<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">222.231.2[.]20<\/span><\/td>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">colorncopy.co[.]kr<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">swr.co[.]kr<\/span><\/td>\n<td width=\"132\">LG DACOM Company<\/td>\n<td width=\"95\">2025\u201103\u201118<\/td>\n<td width=\"170\">Compromised South Korean website used to host shellcode.<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">222.231.2[.]23<\/span><\/td>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">sejonghaeun[.]com<\/span><\/td>\n<td width=\"132\">IP Supervisor<\/td>\n<td width=\"95\">2025\u201103\u201118<\/td>\n<td width=\"170\">Compromised South Korean website used to host clear mono library.<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">222.231.2[.]41<\/span><\/td>\n<td width=\"123\"><span style=\"font-family: courier new, courier, monospace;\">cndsoft.co[.]kr<\/span><\/td>\n<td width=\"132\">IP Supervisor<\/td>\n<td width=\"95\">2025\u201103\u201118<\/td>\n<td width=\"170\">Compromised South Korean website used to host shellcode.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>MITRE ATT&amp;CK strategies<\/h2>\n<p>This desk was constructed utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/resources\/versions\/\">model 18<\/a> of the MITRE ATT&amp;CK Enterprise framework.<\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"113\"><strong>Tactic<\/strong><\/td>\n<td width=\"113\"><strong>ID<\/strong><\/td>\n<td width=\"151\"><strong>Identify<\/strong><\/td>\n<td width=\"265\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td rowspan=\"4\" width=\"113\"><strong>Useful resource Growth<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1584\/004\">T1584.004<\/a><\/td>\n<td width=\"151\">Compromise Infrastructure: Server<\/td>\n<td width=\"265\">ScarCruft compromised South Korean web sites to host payloads and configurations.<br \/>ScarCruft compromised the sqgame web site to carry out a supply-chain assault.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1585\/003\">T1585.003<\/a><\/td>\n<td width=\"151\">Set up Accounts: Cloud Accounts<\/td>\n<td width=\"265\">ScarCruft created Zoho WorkDrive accounts and used their cloud storage drives for C&amp;C functions.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1587\/001\">T1587.001<\/a><\/td>\n<td width=\"151\">Develop Capabilities: Malware<\/td>\n<td width=\"265\">ScarCruft developed the Android model of the BirdCall backdoor.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1608\/001\">T1608.001<\/a><\/td>\n<td width=\"151\">Stage Capabilities: Add Malware<\/td>\n<td width=\"265\">ScarCruft uploaded trojanized video games to the compromised sqgame web site.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Preliminary Entry<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1195\/002\">T1195.002<\/a><\/td>\n<td width=\"151\">Provide Chain Compromise: Compromise Software program Provide Chain<\/td>\n<td width=\"265\">ScarCruft compromised an sqgame replace server to distribute malicious updates.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Execution<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1059\/003\">T1059.003<\/a><\/td>\n<td width=\"151\">Command and Scripting Interpreter: Home windows Command Shell<\/td>\n<td width=\"265\">BirdCall can execute shell instructions.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"6\" width=\"113\"><strong>Protection Evasion<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1027\/013\">T1027.013<\/a><\/td>\n<td width=\"151\">Obfuscated Information or Data: Encrypted\/Encoded File<\/td>\n<td width=\"265\">BirdCall has encrypted strings and loading chain elements.<br \/>The trojanized mono library incorporates encrypted shellcode.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1070\/004\">T1070.004<\/a><\/td>\n<td width=\"151\">Indicator Elimination: File Deletion<\/td>\n<td width=\"265\">The trojanized mono library is changed with a clear one.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1112\">T1112<\/a><\/td>\n<td width=\"151\">Modify Registry<\/td>\n<td width=\"265\">BirdCall can modify settings of phrase processors to allow macros.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1140\">T1140<\/a><\/td>\n<td width=\"151\">Deobfuscate\/Decode Information or Data<\/td>\n<td width=\"265\">BirdCall decrypts strings and loading chain elements.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1480\/001\">T1480.001<\/a><\/td>\n<td width=\"151\">Execution Guardrails: Environmental Keying<\/td>\n<td width=\"265\">BirdCall\u2019s loading chain has elements encrypted with a computer-specific key.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1497\">T1497<\/a><\/td>\n<td width=\"151\">Virtualization\/Sandbox Evasion<\/td>\n<td width=\"265\">The downloader within the trojanized mono library checks for evaluation instruments and digital machine environments.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Credential Entry<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1555\">T1555<\/a><\/td>\n<td width=\"151\">Credentials from Password Shops<\/td>\n<td width=\"265\">BirdCall can get hold of saved passwords from browsers and different software program.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"3\" width=\"113\"><strong>Discovery<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1046\">T1046<\/a><\/td>\n<td width=\"151\">Community Service Discovery<\/td>\n<td width=\"265\">BirdCall can scan a variety of IPs and ports with an HTTP GET request.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1082\">T1082<\/a><\/td>\n<td width=\"151\">System Data Discovery<\/td>\n<td width=\"265\">BirdCall can get hold of varied system info.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1083\">T1083<\/a><\/td>\n<td width=\"151\">File and Listing Discovery<\/td>\n<td width=\"265\">BirdCall can get hold of details about drives and directories.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"7\" width=\"113\"><strong>Assortment<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1005\">T1005<\/a><\/td>\n<td width=\"151\">Information from Native System<\/td>\n<td width=\"265\">BirdCall can accumulate person recordsdata from IM purchasers KakaoTalk, WeChat, and Sign.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1056\/001\">T1056.001<\/a><\/td>\n<td width=\"151\">Enter Seize: Keylogging<\/td>\n<td width=\"265\">BirdCall can log keystrokes.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1113\">T1113<\/a><\/td>\n<td width=\"151\">Display Seize<\/td>\n<td width=\"265\">BirdCall can seize screenshots.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1115\">T1115<\/a><\/td>\n<td width=\"151\">Clipboard Information<\/td>\n<td width=\"265\">BirdCall can accumulate clipboard contents.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1119\">T1119<\/a><\/td>\n<td width=\"151\">Automated Assortment<\/td>\n<td width=\"265\">BirdCall can periodically accumulate recordsdata with sure extensions from native and detachable drives.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1125\">T1125<\/a><\/td>\n<td width=\"151\">Video Seize<\/td>\n<td width=\"265\">BirdCall can seize a webcam photograph.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1560\">T1560<\/a><\/td>\n<td width=\"151\">Archive Collected Information<\/td>\n<td width=\"265\">BirdCall compresses and encrypts collected knowledge earlier than exfiltration.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"3\" width=\"113\"><strong>Command and Management<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1071\/001\">T1071.001<\/a><\/td>\n<td width=\"151\">Utility Layer Protocol: Net Protocols<\/td>\n<td width=\"265\">BirdCall makes use of HTTP to speak with cloud storage companies.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1090\">T1090<\/a><\/td>\n<td width=\"151\">Proxy<\/td>\n<td width=\"265\">BirdCall can act as a proxy.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1102\/002\">T1102.002<\/a><\/td>\n<td width=\"151\">Net Service: Bidirectional Communication<\/td>\n<td width=\"265\">BirdCall communicates with cloud storage companies to obtain instructions and exfiltrate knowledge.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"3\" width=\"113\"><strong>Exfiltration<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1020\">T1020<\/a><\/td>\n<td width=\"151\">Automated Exfiltration<\/td>\n<td width=\"265\">BirdCall periodically exfiltrates collected knowledge.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1041\">T1041<\/a><\/td>\n<td width=\"151\">Exfiltration Over C2 Channel<\/td>\n<td width=\"265\">BirdCall exfiltrates knowledge to its C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1567\/002\">T1567.002<\/a><\/td>\n<td width=\"151\">Exfiltration Over Net Service: Exfiltration to Cloud Storage<\/td>\n<td width=\"265\">BirdCall exfiltrates knowledge to cloud storage companies.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This desk was constructed utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/resources\/versions\/\">model 18<\/a> of the MITRE ATT&amp;CK Cellular framework.<\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td style=\"width: 111.844px;\" width=\"113\"><strong>Tactic<\/strong><\/td>\n<td style=\"width: 111.453px;\" width=\"113\"><strong>ID<\/strong><\/td>\n<td style=\"width: 149.328px;\" width=\"151\"><strong>Identify<\/strong><\/td>\n<td style=\"width: 259.375px;\" width=\"265\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 111.844px;\" width=\"113\"><strong>Preliminary Entry<\/strong><\/td>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1474\/003\">T1474.003<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Provide Chain Compromise: Compromise Software program Provide Chain<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">ScarCruft carried out a supply-chain assault, compromising the sqgame web site, to distribute trojanized video games containing the Android BirdCall backdoor.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.844px;\" rowspan=\"3\" width=\"113\"><strong>Protection Evasion<\/strong><\/td>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1406\">T1406<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Obfuscated Information or Data<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Model 2.0 of the Android BirdCall backdoor is obfuscated.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1407\">T1407<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Obtain New Code at Runtime<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">The Android BirdCall backdoor can obtain and cargo newer variations of itself.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1541\">T1541<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Foreground Persistence<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall makes use of the <span style=\"font-family: courier new, courier, monospace;\">startForeground<\/span> API to take screenshots whereas within the background.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.844px;\" rowspan=\"3\" width=\"113\"><strong>Discovery<\/strong><\/td>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1420\">T1420<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">File and Listing Discovery<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall creates a listing itemizing and searches for recordsdata with specified extensions.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1422\">T1422<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Native Community Configuration Discovery<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall obtains the system\u2019s IMEI, IP tackle, and MAC tackle.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1426\">T1426<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">System Data Discovery<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall obtains system info of the compromised system together with model, mannequin, OS model, kernel model, rooted standing, battery temperature, RAM, and storage info.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.844px;\" rowspan=\"8\" width=\"113\"><strong>Assortment<\/strong><\/td>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1532\">T1532<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Archive Collected Information<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall compresses and encrypts collected knowledge.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1429\">T1429<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Audio Seize<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall can report voice utilizing the microphone.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1430\">T1430<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Location Monitoring<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall obtains approximate system location utilizing the <span style=\"font-family: courier new, courier, monospace;\">ipinfo[.]io<\/span> service.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1513\">T1513<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Display Seize<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall can take screenshots.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1533\">T1533<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Information from Native System<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall collects native recordsdata with the next extensions: <span style=\"font-family: courier new, courier, monospace;\">.jpg<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.doc<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.docx<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.xls<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.xlsx<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.ppt<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.pptx<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.txt<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.hwp<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.pdf<\/span>, <span style=\"font-family: courier new, courier, monospace;\">.m4a<\/span>, and <span style=\"font-family: courier new, courier, monospace;\">.p12<\/span>.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1636\/002\">T1636.002<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Protected Person Information: Name Log<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall collects the decision log.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1636\/003\">T1636.003<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Protected Person Information: Contact Record<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall collects the contact record.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1636\/004\">T1636.004<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Protected Person Information: SMS Messages<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall collects SMS messages.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.844px;\" rowspan=\"2\" width=\"113\"><strong>Command and Management<\/strong><\/td>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1437\/001\">T1437.001<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Utility Layer Protocol: Net Protocols<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall communicates with the C&amp;C cloud storage drive utilizing HTTPS.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1481\/002\">T1481.002<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Net Service: Bidirectional Communication<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall makes use of a Zoho WorkDrive service cloud storage drive for C&amp;C functions.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 111.844px;\" width=\"113\"><strong>Exfiltration<\/strong><\/td>\n<td style=\"width: 111.453px;\" width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v18\/techniques\/T1646\">T1646<\/a><\/td>\n<td style=\"width: 149.328px;\" width=\"151\">Exfiltration Over C2 Channel<\/td>\n<td style=\"width: 259.375px;\" width=\"265\">Android BirdCall makes use of the C&amp;C channel for knowledge exfiltration.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/eti-eset-threat-intelligence.png\" alt=\"\" width=\"915\" height=\"296\"\/><\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>ESET researchers uncovered a multiplatform supply-chain assault by North Korea-aligned APT group ScarCruft, focusing on the Yanbian area in China \u2013 residence to ethnic Koreans and a crossing level for North Korean refugees and defectors. Within the assault, in all probability ongoing since late 2024, ScarCruft compromised Home windows and Android elements of a online [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17120,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[717,9940,748,630,9939,8250],"class_list":["post-17118","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-attack","tag-compromises","tag-gaming","tag-platform","tag-scarcruft","tag-supplychain"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17118"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17118\/revisions"}],"predecessor-version":[{"id":17119,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17118\/revisions\/17119"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17120"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-27 01:53:22 UTC -->